CVE-2024-41109

Source
https://cve.org/CVERecord?id=CVE-2024-41109
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41109.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-41109
Aliases
Published
2024-07-30T14:43:14.407Z
Modified
2026-03-14T12:35:36.697458Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Pimcore vulnerable to disclosure of system and database information behind /admin firewall
Details

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to /admin/index/statistics with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their row count in the system. This vulnerability is fixed in 1.5.2, 1.4.6, and 1.3.10.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41109.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/pimcore/admin-ui-classic-bundle

Affected ranges

Type
GIT
Repo
https://github.com/pimcore/admin-ui-classic-bundle
Events

Affected versions

v1.*
v1.5.0
v1.5.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41109.json"