Back

MEDIUM

Cross-site Scripting (XSS) - Reflected in pimcore/pimcore

Published Sep 21, 2022

Description

If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Sep 21, 2022
Updated May 28, 2025
Reserved Sep 21, 2022
CISA Vulnrichment
Updated May 28, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-WQR6-57QM-HHR5