pimcore/pimcore is vulnerable to Insufficient Session Expiration
50
Medium Risk
Affected versions of this package are vulnerable to Insufficient Session Expiration on password update, where the implemented feature did not automatically revoke existing sessions and enforce re-authentication after a password change, allowing an attacker with a previously compromised session to maintain unauthorized access to the user's account and perform malicious actions until the session expires or is manually terminated.
You are affected if you are using a version that falls within the vulnerable range.
pimcore/pimcore is vulnerable to Insufficient Session Expiration in versions 10.6.0 - 12.1.5.
Upgrade the pimcore/pimcore library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant