PT-2024-19008 · Pimcore · Pimcore Customer Management Framework

Wisconaut

·

Published

2024-01-10

·

Updated

2024-01-18

·

CVE-2024-21666

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pimcore Customer Management Framework versions prior to 4.0.6
Description The issue allows an authenticated and unauthorized user to access the list of potential duplicate users and see their data. This occurs because permissions are not properly enforced when reaching the "/admin/customermanagementframework/duplicates/list" endpoint, allowing an authenticated user without the necessary permissions to access the endpoint and query the available data. As a result, unauthorized users can access personally identifiable information (PII) from customers.
Recommendations For versions prior to 4.0.6, update to version 4.0.6 to resolve the issue. As a temporary workaround, consider restricting access to the "/admin/customermanagementframework/duplicates/list" endpoint until the update is applied. Additionally, review and adjust user roles and permissions to ensure that only authorized users have access to sensitive customer data.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-21666
GHSA-C38C-C8MH-VQ68

Affected Products

Pimcore Customer Management Framework