Description
Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a logged in user could open a preview. This no longer applies. Previews are broad open to any user and with just the hint of a restricted link one could gain access to possible confident / unreleased information. This vulnerability is fixed in 11.2.2 and 11.1.6.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 05 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-05T14:31:39.567Z
Reserved: 2024-03-18T17:07:00.095Z
Link: CVE-2024-29197
Updated: 2024-08-02T01:10:54.523Z
Status : Analyzed
Published: 2024-03-26T15:15:49.390
Modified: 2025-11-05T22:18:50.877
Link: CVE-2024-29197
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:39Z
Weaknesses