
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-0832 is a Stored Cross-site Scripting (XSS) vulnerability identified in GitHub repository pimcore/pimcore versions prior to 10.3.3. The vulnerability was discovered and reported on March 2, 2022 (CVE Mitre).
The vulnerability exists in the SERP preview functionality where title and description fields were not properly escaped before being displayed. The fix involved implementing proper HTML escaping using htmlspecialchars() function for both title and description values in the preview (GitHub Commit).
This stored XSS vulnerability could allow attackers to inject malicious scripts that would be executed in the context of other users' browsers when viewing the affected SERP preview, potentially leading to session hijacking, data theft, or other malicious actions (Huntr Report).
Users should upgrade to Pimcore version 10.3.3 or later which contains the fix for this vulnerability. The patch implements proper HTML escaping for the affected fields in the SERP preview functionality (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."