{"id":"GHSA-rrwm-8wqm-gwgv","aliases":[],"url":"https://o3.security/vulnerability/GHSA-rrwm-8wqm-gwgv","summary":"Cross-site Scripting (XSS) - stored in Print Documents","details":"### Impact\nStored xss leads to steal cookies and other information of other users\n\n### Patches\nUpdate to version 10.5.19 or apply this patch manually https://github.com/pimcore/pimcore/pull/14560.patch\n\n### Workarounds\nApply https://github.com/pimcore/pimcore/pull/14560.patch manually.\n\n### References\nhttps://huntr.dev/bounties/31d97442-3f87-439f-83f0-1c7862ef0c7c/\n","published":"2023-03-16T18:33:28Z","modified":"2024-11-30T05:52:18.219129Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"10.5.19"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/pimcore/pimcore/security/advisories/GHSA-rrwm-8wqm-gwgv"},{"type":"PACKAGE","url":"https://github.com/pimcore/pimcore"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-30T05:52:18.219129Z"}}