CVE-2023-32062
27.11.2023, 22:15
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.Enginsight
Vendor | Product | Version |
---|---|---|
oroinc | oroplatform | 4.2.0 ≤ 𝑥 ≤ 4.2.6 |
oroinc | oroplatform | 5.0.0 ≤ 𝑥 < 5.0.7 |
oroinc | oroplatform | 5.1.0 ≤ 𝑥 < 5.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References