
Cloud Vulnerability DB
A community-led vulnerabilities database
A Stored Cross-site Scripting (XSS) vulnerability was identified in GitHub repository pimcore/pimcore versions prior to 10.5.6. The vulnerability was discovered and recorded on September 14, 2022 (CVE List).
The vulnerability is classified as a Stored Cross-site Scripting (XSS) issue affecting the Pimcore platform. The issue was related to unescaped values in the UI components, specifically in the properties, notifications, and panel sections of the admin interface (GitHub Commit).
The vulnerability could allow attackers to inject malicious scripts that would be stored and executed in the context of the application's admin interface, potentially affecting administrators and other privileged users accessing the Pimcore platform (CVE List).
The issue was fixed by implementing proper HTML encoding for values displayed in the UI. The fix includes escaping values in properties, notifications, and panel components using Ext.util.Format.htmlEncode(). Users should upgrade to Pimcore version 10.5.6 or later to receive the security fix (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."