← Back

CVE-2024-41109

nvd nist
Published: Jul 30, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their row count in the system. This vulnerability is fixed in 1.5.2, 1.4.6, and 1.3.10.

Affected (3)

1 product
Admin Classic Bundle
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Pimcore
Before 1.3.10
From 1.4.0 to 1.4.6
From 1.5.0 to 1.5.2

Timeline

No history available yet.