GHSA-6f58-j323-6472
GitHub Security Advisory
pimcore/admin-ui-classic-bundle Unverified Password Change
Advisory Details
### Impact
As old password can be set as new password , it is considered as password policy violation.
Pimcore is not enforcing strict password policy which allow attacker to set old password as new password
Proof of Concept
1. Go to Admin link
2. login and click on -> "User | My Profile".
3. Go to change password now put old password as new password and click save.
### Patches
https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch
### Workarounds
Update to version 1.2.0 or apply this patches manually
https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch
### References
https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021/
Affected Packages
Related CVEs
Key Information
Dataset
Data from GitHub Advisory Database. This information is provided for research and educational purposes.