SB2024073068 - Information disclosure in Pimcore admin-ui-classic-bundle
Published: July 30, 2024 Updated: July 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Information disclosure (CVE-ID: CVE-2024-41109)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive system and database information.
The vulnerability exists due to improper access control in the /admin/index/statistics endpoint when handling requests from a logged-in Pimcore session. A remote user can request the endpoint to disclose sensitive system and database information.
The response may expose the Pimcore installation version, PHP version, MySQL version, installed bundles, and database table names with row counts.
Remediation
Install update from vendor's website.