Observable Response Discrepancy in Pimcore admin-ui-classic-bundle - CVE-2025-24980
Published: February 7, 2025 / Updated: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose valid account information.
The vulnerability exists due to observable response discrepancy in the forgot password function when handling password reset requests. A remote attacker can submit email addresses to determine whether an account exists to disclose valid account information.