CVE-2023-32063

OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oroinc:client_relationship_management:*:*:*:*:*:*:*:*
cpe:2.3:a:oroinc:client_relationship_management:*:*:*:*:*:*:*:*
cpe:2.3:a:oroinc:client_relationship_management:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-11-28 04:15

Updated : 2023-12-01 21:46


NVD link : CVE-2023-32063

Mitre link : CVE-2023-32063

CVE.ORG link : CVE-2023-32063


JSON object : View

Products Affected

oroinc

  • client_relationship_management
CWE
CWE-284

Improper Access Control