Pimcore User Enumeration

medium Web App Scanning Plugin ID 114089

Language:

Synopsis

Pimcore User Enumeration

Description

Pimcore versions before 10.1.3 suffer from an user enumeration vulnerability through the administration panel lost password feature. By submitting multiple usernames, a remote and unauthenticated attacker can infer the valid administrative accounts on the target Pimcore instance.

Solution

Upgrade to Pimcore version 10.1.3 or latest.

See Also

https://github.com/pimcore/pimcore/security/advisories/GHSA-579x-cjvr-cqj9

Plugin Details

Severity: Medium

ID: 114089

Type: remote

Published: 10/25/2023

Updated: 1/24/2024

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2021-39189

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: CVE-2021-39189

Vulnerability Information

CPE: cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 9/15/2021

Reference Information

CVE: CVE-2021-39189