PT-2022-13554 · Pimcore · Pimcore/Data-Hub

Published

2022-03-24

·

Updated

2024-03-06

·

CVE-2022-0955

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pimcore/data-hub versions prior to 1.2.4
Description The issue is related to stored Cross-site Scripting (XSS) in the pimcore/data-hub GitHub repository. This type of attack occurs when an application stores user input data without proper validation or encoding, allowing an attacker to inject malicious scripts. An admin user accessing Datahub can trigger the attack, potentially resulting in the user's cookie being stolen.
Recommendations For versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Datahub repository to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-PIMCORE-2022-0955
CVE-2022-0955
GHSA-VC5R-XFC4-4X22

Affected Products

Pimcore/Data-Hub