Observable Response Discrepancy in Lost Password Service
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 1.3%
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
nono source reports it
In short
Pimcore's password reset feature reveals whether a username exists in the system through observable differences in the response, allowing attackers to discover valid user accounts.
Technical detail
An attacker can enumerate valid usernames by submitting password reset requests and observing response discrepancies (CWE-204), which leak information about account existence without authentication. This requires only network access to the forgot password endpoint and impacts confidentiality of user account information.
Summary generated and translated by AI from the official description.
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
pimcore · pimcore