CVE-2023-32064
28.11.2023, 04:15
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1.Enginsight
| Vendor | Product | Version |
|---|---|---|
| oroinc | orocommerce | 4.2.0 ≤ 𝑥 ≤ 4.2.8 |
| oroinc | orocommerce | 5.0.0 ≤ 𝑥 < 5.0.11 |
| oroinc | orocommerce | 5.1.0 ≤ 𝑥 < 5.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration