OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-3058 OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
Github GHSA Github GHSA GHSA-x2xm-p6vq-482g OroCalendarBundle has incorrect system calendar events visibility
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T15:03:28.737Z

Reserved: 2023-05-01T16:47:35.313Z

Link: CVE-2023-32062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-27T22:15:07.660

Modified: 2024-11-21T08:02:38.223

Link: CVE-2023-32062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.