pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Fri, 07 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Description pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Title User enumeration in pimcore/admin-ui-classic-bundle
Weaknesses CWE-204
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-07T21:13:39.898Z

Reserved: 2025-01-29T15:18:03.212Z

Link: CVE-2025-24980

cve-icon Vulnrichment

Updated: 2025-02-07T21:13:34.757Z

cve-icon NVD

Status : Received

Published: 2025-02-07T20:15:33.933

Modified: 2025-02-07T22:15:14.617

Link: CVE-2025-24980

cve-icon Redhat

No data.