Input validation error in Pimcore admin-ui-classic-bundle - CVE-2024-25625
Published: February 19, 2024 / Updated: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to conduct phishing attacks.
The vulnerability exists due to improper input validation in the UserController invitationLinkAction function when handling POST requests to the /admin/user/invitationlink endpoint. A remote privileged user can supply a crafted Host header to conduct phishing attacks.
User interaction is required because the victim must use the invitation link sent by email.