Pimcore Admin Classic Bundle allows user enumeration
Moderate severity
GitHub Reviewed
Published
Feb 7, 2025
in
pimcore/admin-ui-classic-bundle
•
Updated Feb 11, 2025
Description
Published by the National Vulnerability Database
Feb 7, 2025
Published to the GitHub Advisory Database
Feb 7, 2025
Reviewed
Feb 7, 2025
Last updated
Feb 11, 2025
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
References