ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-0339 | ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10. | 
  Github GHSA | 
                GHSA-cx99-25hr-5jxf | Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-17T21:09:16.034Z
Reserved: 2023-12-29T16:10:20.367Z
Link: CVE-2024-21665
Updated: 2025-06-17T21:06:56.583Z
Status : Modified
Published: 2024-01-11T01:15:45.413
Modified: 2024-11-21T08:54:49.570
Link: CVE-2024-21665
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA