← Vulnerability feed

Vulnerability record · CVE-2024-49370 · published 23 October 2024

CVE-2024-49370: Pimcore vulnerability

Pimcore · Pimcore

Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimcore portal engine versions 4.1.7 and 3.1.16, the password is then set without hashing so it can be read by everyone. Everyone who combines PortalUser to PimcoreUsers and change passwords via profile settings could be affected. Versions 4.1.7 and 3.1.16 of the Pimcore portal engine fix the issue.

8.7 CVSS 4.0 High EPSS 0.52% · top 57.8% CWE-256 · CWE-256
8.7CVSS 4.0 base score
0.52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimcore portal engine versions 4.1.7 and 3.1.16, the password is then set without hashing so it can be read by everyone. Everyone who combines PortalUser to PimcoreUsers and change passwords via profile settings could be affected. Versions 4.1.7 and 3.1.16 of the Pimcore portal engine fix the issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-49370 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-39365Pimcore code injection vulnerabilityPimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/…EPSS 1.8%9.8CVE-2019-18981Pimcore vulnerabilityPimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.EPSS 1.4%9.8CVE-2019-18985Pimcore improper restriction of authentication attempts vulnerabilityPimcore before 6.2.2 lacks brute force protection for the 2FA token.EPSS 1.4%9.0CVE-2021-4139Pimcore cross-site scripting vulnerabilitypimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.88%8.8CVE-2023-47637Pimcore sql injection vulnerabilityPimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` endpoint calls `getFilterConditi…EPSS 1.2%8.8CVE-2023-38708Pimcore path traversal vulnerabilityPimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path traversal vulnerability exist…EPSS 0.64%8.8CVE-2023-2983Pimcore vulnerabilityPrivilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.EPSS 0.92%8.8CVE-2023-2984Pimcore vulnerabilityPath Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2024-49370), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.