The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions are enforced when reaching the `/admin/customermanagementframework/duplicates/list` endpoint allowing an authenticated user without the permissions to access the endpoint and query the data available there. Unauthorized user(s) can access PII data from customers. This vulnerability has been patched in version 4.0.6.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-01-11T00:45:44.520Z

Updated: 2024-08-01T22:27:35.774Z

Reserved: 2023-12-29T16:10:20.368Z

Link: CVE-2024-21666

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-11T01:15:45.623

Modified: 2024-01-18T13:20:45.647

Link: CVE-2024-21666

cve-icon Redhat

No data.