PT-2024-5575 · Pimcore · Pimcore Admin Classic Bundle

Mysliwietzflorian

·

Published

2024-07-15

·

Updated

2024-08-11

·

CVE-2024-41109

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pimcore Admin Classic Bundle versions prior to 1.3.10 Pimcore Admin Classic Bundle versions prior to 1.4.6 Pimcore Admin Classic Bundle versions prior to 1.5.2
Description Navigating to "/admin/index/statistics" with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles, and all database tables and their row count in the system. The web server should not return any product and version information of the components used. The table names and row counts should not be exposed. The "/admin/index/statistics" endpoint returns a JSON-response containing sensitive information.
Recommendations For Pimcore Admin Classic Bundle versions prior to 1.3.10, update to version 1.3.10 or later. For Pimcore Admin Classic Bundle versions prior to 1.4.6, update to version 1.4.6 or later. For Pimcore Admin Classic Bundle versions prior to 1.5.2, update to version 1.5.2 or later. As a temporary workaround, consider restricting access to the "/admin/index/statistics" endpoint to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-06256
CVE-2024-41109
GHSA-FX6J-9PP6-PH36

Affected Products

Pimcore Admin Classic Bundle