pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Tue, 04 Nov 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Pimcore
Pimcore admin Classic Bundle
CPEs cpe:2.3:a:pimcore:admin_classic_bundle:*:*:*:*:*:pimcore:*:*
Vendors & Products Pimcore
Pimcore admin Classic Bundle
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Fri, 07 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Description pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Title User enumeration in pimcore/admin-ui-classic-bundle
Weaknesses CWE-204
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-02-07T19:56:10.439Z

Updated: 2025-02-07T21:13:39.898Z

Reserved: 2025-01-29T15:18:03.212Z

Link: CVE-2025-24980

cve-icon Vulnrichment

Updated: 2025-02-07T21:13:34.757Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-07T20:15:33.933

Modified: 2025-11-04T19:49:39.810

Link: CVE-2025-24980

cve-icon Redhat

No data.