Information disclosure in Pimcore admin-ui-classic-bundle - CVE-2024-41109

 

Information disclosure in Pimcore admin-ui-classic-bundle - CVE-2024-41109

Published: July 30, 2024 / Updated: July 22, 2026


Vulnerability identifier: #VU139119
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41109
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive system and database information.

The vulnerability exists due to improper access control in the /admin/index/statistics endpoint when handling requests from a logged-in Pimcore session. A remote user can request the endpoint to disclose sensitive system and database information.

The response may expose the Pimcore installation version, PHP version, MySQL version, installed bundles, and database table names with row counts.


Affected software

Pimcore admin-ui-classic-bundle

How to mitigate CVE-2024-41109

Install security update from vendor's website.

Pimcore admin-ui-classic-bundle - addressed in versions 1.3.10, 1.4.6, 1.5.2

External References

Related Security Bulletins