SB2024073068 - Information disclosure in Pimcore admin-ui-classic-bundle



SB2024073068 - Information disclosure in Pimcore admin-ui-classic-bundle

Published: July 30, 2024 Updated: July 22, 2026

Security Bulletin ID SB2024073068
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Information disclosure (CVE-ID: CVE-2024-41109)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive system and database information.

The vulnerability exists due to improper access control in the /admin/index/statistics endpoint when handling requests from a logged-in Pimcore session. A remote user can request the endpoint to disclose sensitive system and database information.

The response may expose the Pimcore installation version, PHP version, MySQL version, installed bundles, and database table names with row counts.


Remediation

Install update from vendor's website.