CVE-2023-32063
28.11.2023, 04:15
OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.Enginsight
Vendor | Product | Version |
---|---|---|
oroinc | client_relationship_management | 4.2.0 ≤ 𝑥 ≤ 4.2.5 |
oroinc | client_relationship_management | 5.0.0 ≤ 𝑥 < 5.0.4 |
oroinc | client_relationship_management | 5.1.0 ≤ 𝑥 < 5.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References