CVE-2023-49075
28.11.2023, 05:15
The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An authenticated user can access the system without having to provide the two factor credentials. This issue has been patched in version 1.2.2.Enginsight
Vendor | Product | Version |
---|---|---|
pimcore | admin_classic_bundle | 𝑥 < 1.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References