Loading HuntDB...

GHSA-6f58-j323-6472

GitHub Security Advisory

pimcore/admin-ui-classic-bundle Unverified Password Change

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact
As old password can be set as new password , it is considered as password policy violation.

Pimcore is not enforcing strict password policy which allow attacker to set old password as new password

Proof of Concept
1. Go to Admin link
2. login and click on -> "User | My Profile".
3. Go to change password now put old password as new password and click save.

### Patches
https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch

### Workarounds
Update to version 1.2.0 or apply this patches manually
https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch

### References
https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021/

Affected Packages

Packagist pimcore/admin-ui-classic-bundle
Affected versions: 0 (fixed in 1.2.0)

Related CVEs

Key Information

GHSA ID
GHSA-6f58-j323-6472
Published
October 31, 2023 10:23 PM
Last Modified
October 31, 2023 10:23 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
pimcore/admin-ui-classic-bundle
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.