Miggo Logo

CVE-2022-1351:
Cross-site Scripting in Pimcore

6.8

CVSS Score

Basic Information

EPSS Score
-
Published
4/15/2022
Updated
1/27/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
pimcore/pimcorecomposer< 10.410.4

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided commit diff and vulnerability details focus on Content Security Policy (CSP) configuration changes (e.g., adding 'exclude_paths' and modifying CSP directives). While these changes mitigate the XSS vulnerability by enforcing stricter CSP policies, the root cause of the stored XSS lies in the Tooltip feature's input handling code, which is not included in the provided diff. The actual vulnerable function(s) responsible for rendering/processing Tooltip content without proper input sanitization are not visible in the analyzed materials. Therefore, no specific functions can be identified with high confidence based on the provided data.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

Pim*or* prior to v*rsion **.* is vuln*r**l* to stor** *ross-sit* s*riptin* in Tooltip.

Reasoning

T** provi*** *ommit *i** *n* vuln*r**ility **t*ils *o*us on *ont*nt S**urity Poli*y (*SP) *on*i*ur*tion ***n**s (*.*., ***in* '*x*lu**_p*t*s' *n* mo*i*yin* *SP *ir**tiv*s). W*il* t**s* ***n**s miti**t* t** XSS vuln*r**ility *y *n*or*in* stri*t*r *SP