The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate users and see their data. Permissions are enforced when reaching the `/admin/customermanagementframework/duplicates/list` endpoint allowing an authenticated user without the permissions to access the endpoint and query the data available there. Unauthorized user(s) can access PII data from customers. This vulnerability has been patched in version 4.0.6.
History

Tue, 03 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-01-11T00:45:44.520Z

Updated: 2025-06-03T14:25:35.995Z

Reserved: 2023-12-29T16:10:20.368Z

Link: CVE-2024-21666

cve-icon Vulnrichment

Updated: 2024-08-01T22:27:35.774Z

cve-icon NVD

Status : Modified

Published: 2024-01-11T01:15:45.623

Modified: 2024-11-21T08:54:49.703

Link: CVE-2024-21666

cve-icon Redhat

No data.