Cross-site Scripting (XSS) - Stored in pimcore/pimcore
Reported on
Feb 16th 2023
Description
- https://11.x-dev.pimcore.fun/admin/
- Go to Settings -> Thumbnails -> Video Thumbnails
- Click the button (Add Media Segment)
- Write : "><img src=x onerror=alert(document.domain)> and then click ok
Impact
excute script
hello they said me https://huntr.dev/bounties/ee86781c-3ca9-4dbc-8315-8ee243fb3b2b/ is duple with this report. please maintainer checks amazing haha