Improper Encoding or Escaping of Output in Asset Metadata Component
Description
Published by the National Vulnerability Database
Sep 1, 2021
Reviewed
Sep 1, 2021
Published to the GitHub Advisory Database
Sep 1, 2021
Last updated
Feb 1, 2023
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.
References