Description
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
Published: 2023-11-27
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-3058 OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
Github GHSA Github GHSA GHSA-x2xm-p6vq-482g OroCalendarBundle has incorrect system calendar events visibility
History

No history.

Subscriptions

Oroinc Oroplatform
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T15:03:28.737Z

Reserved: 2023-05-01T16:47:35.313Z

Link: CVE-2023-32062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-27T22:15:07.660

Modified: 2024-11-21T08:02:38.223

Link: CVE-2023-32062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses