Improper access control in Pimcore admin-ui-classic-bundle - CVE-2024-24822
Published: February 7, 2024 / Updated: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to modify tags without authorization.
The vulnerability exists due to improper access control in tag management functionality when handling tag creation or deletion requests. A remote user can send crafted parameters to modify tags without authorization.
This can affect the integrity and availability of data in the admin panel.