Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their row count in the system. This vulnerability is fixed in 1.5.2, 1.4.6, and 1.3.10.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2340 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their row count in the system. This vulnerability is fixed in 1.5.2, 1.4.6, and 1.3.10. |
Github GHSA |
GHSA-fx6j-9pp6-ph36 | Pimcore vulnerable to disclosure of system and database information behind /admin firewall |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pimcore
Pimcore admin Classic Bundle |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:pimcore:admin_classic_bundle:*:*:*:*:*:pimcore:*:* | |
| Vendors & Products |
Pimcore
Pimcore admin Classic Bundle |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:46:52.472Z
Reserved: 2024-07-15T15:53:28.321Z
Link: CVE-2024-41109
Updated: 2024-08-02T04:46:52.472Z
Status : Analyzed
Published: 2024-07-30T15:15:12.890
Modified: 2025-11-04T18:01:13.433
Link: CVE-2024-41109
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA