Information disclosure in Pimcore admin-ui-classic-bundle - CVE-2024-41109
Published: July 30, 2024 / Updated: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive system and database information.
The vulnerability exists due to improper access control in the /admin/index/statistics endpoint when handling requests from a logged-in Pimcore session. A remote user can request the endpoint to disclose sensitive system and database information.
The response may expose the Pimcore installation version, PHP version, MySQL version, installed bundles, and database table names with row counts.