Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr5f-php7-rg24

Опубликовано: 07 фев. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Pimcore Admin Classic Bundle allows user enumeration

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Пакеты

Наименование

pimcore/admin-ui-classic-bundle

composer
Затронутые версииВерсия исправления

< 1.7.4

1.7.4

EPSS

Процентиль: 0%
0.00005
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 5.3
nvd
12 месяцев назад

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 0%
0.00005
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-204