CVE-2025-24980
MEDIUMDescription
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.7.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Is your site exposed to CVE-2025-24980?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| pimcore | admin_classic_bundle |
References
Advisories & Patches
Exploits
Frequently Asked Questions
What is CVE-2025-24980? +
How severe is CVE-2025-24980? +
What products are affected by CVE-2025-24980? +
How do I check if I'm vulnerable to CVE-2025-24980? +
Related Vulnerabilities
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other …
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well …
User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker …
IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumerate valid users by exploiting the …
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an …
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` …