Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a logged in user could open a preview. This no longer applies. Previews are broad open to any user and with just the hint of a restricted link one could gain access to possible confident / unreleased information. This vulnerability is fixed in 11.2.2 and 11.1.6.1.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 05 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:* |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-05T14:31:39.567Z
Reserved: 2024-03-18T17:07:00.095Z
Link: CVE-2024-29197
Updated: 2024-08-02T01:10:54.523Z
Status : Analyzed
Published: 2024-03-26T15:15:49.390
Modified: 2025-11-05T22:18:50.877
Link: CVE-2024-29197
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:39Z
Weaknesses