Intel

AIKIDO-2025-10667

pimcore/pimcore is vulnerable to Insufficient Session Expiration

Insufficient Session Expiration Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 7, 2025

50

Medium Risk

This Affects:

PHPpimcore/pimcore
10.6.0 - 12.1.5
Fixed in 12.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Insufficient Session Expiration on password update, where the implemented feature did not automatically revoke existing sessions and enforce re-authentication after a password change, allowing an attacker with a previously compromised session to maintain unauthorized access to the user's account and perform malicious actions until the session expires or is manually terminated.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

pimcore/pimcore is vulnerable to Insufficient Session Expiration in versions 10.6.0 - 12.1.5.

How to fix this

Upgrade the pimcore/pimcore library to the patch version.