CVE-2024-49370 - CVE House
Back to Database
Status published High CVE-2024-49370

Change-Password via Portal-Profile sets PimcoreBackendUser password without hashing

Vulnerability Description

Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimcore portal engine versions 4.1.7 and 3.1.16, the password is then set without hashing so it can be read by everyone. Everyone who combines PortalUser to PimcoreUsers and change passwords via profile settings could be affected. Versions 4.1.7 and 3.1.16 of the Pimcore portal engine fix the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-49370

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

pimcore
Vulnerable Versions:
< 3.1.16, >= 4.0.0, < 4.1.7

Timeline

Official Publish: October 23rd, 2024
Last Modified: October 23rd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)