HomePimcoreCVE-2025-24980

CVE-2025-24980

MEDIUM
6.9CVSS
Published: 2025-02-07
Updated: 2026-01-16
AI Analysis

Description

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Metrics

Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Confidentiality
undefined
Integrity
undefined
Availability
undefined
Weaknesses
CWE-204

Metadata

Primary Vendor
PIMCORE
Published
2/7/2025
Last Modified
1/16/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

pimcore : admin_classic_bundle

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-24980 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com