Unverified Password Change in Pimcore admin-ui-classic-bundle - CVE-2023-5844
Published: October 30, 2023 / Updated: July 22, 2026
Pimcore admin-ui-classic-bundle
Detailed vulnerability description
The vulnerability allows a remote user to bypass password policy requirements.
The vulnerability exists due to unverified password change in the password change functionality when changing a password through the profile settings. A remote user can submit the old password as the new password to bypass password policy requirements.