Pimcore prior to 10.4.0 is vulnerable to stored cross-site scripting. References https://nvd.nist.gov/vuln/detail/CVE-2022-0893 https://github.com/pimcore/pimcore/commit/6e0922c5b2959ac1b48500ac508d8fc5a97286f9 https://huntr.dev/bounties/2859a1c1-941c-4efc-a3ad-a0657c7a77e9 https://github.com/pimcore/pimcore/pull/11447 https://github.com/advisories/GHSA-g795-4hxx-qqwm