Description
An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
v12.3.3
Credits
Oscar Naveda
Fluid Attacks' AI SAST Scanner
References
fluidattacks.com/es/advisories/mago
github.com/pimcore/pimcore/