Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2021-09-15T13:50:13

Updated: 2024-08-04T01:58:18.264Z

Reserved: 2021-08-16T00:00:00

Link: CVE-2021-39189

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-15T14:15:08.997

Modified: 2021-09-27T20:13:17.483

Link: CVE-2021-39189

cve-icon Redhat

No data.