GHSA-vr5f-php7-rg24

Suggest an improvement
Source
https://github.com/advisories/GHSA-vr5f-php7-rg24
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-vr5f-php7-rg24/GHSA-vr5f-php7-rg24.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vr5f-php7-rg24
Aliases
Published
2025-02-07T20:27:43Z
Modified
2025-02-11T17:25:44.018147Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Pimcore Admin Classic Bundle allows user enumeration
Details

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": "2025-02-07T20:15:33Z",
    "cwe_ids": [
        "CWE-204"
    ],
    "github_reviewed_at": "2025-02-07T20:27:43Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / pimcore/admin-ui-classic-bundle

Package

Name
pimcore/admin-ui-classic-bundle
Purl
pkg:composer/pimcore/admin-ui-classic-bundle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.4

Affected versions

v1.*
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0-RC1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2
v1.2.0-RC1
v1.2.1
v1.2.2
v1.2.3
v1.3.0-RC1
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.5.0-RC1
v1.5.0-RC2
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.6.0-RC1
v1.6.0-RC2
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
1.*
1.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-vr5f-php7-rg24/GHSA-vr5f-php7-rg24.json"