Cross-site scripting in Pimcore admin-ui-classic-bundle - #VU139120
Published: June 4, 2024 / Updated: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.
The vulnerability exists due to cross-site scripting in jQuery DOM manipulation methods when processing html content from untrusted sources. A remote attacker can supply crafted html to trigger script execution in the victim's browser.