Description
ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0339 | ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10. |
Github GHSA |
GHSA-cx99-25hr-5jxf | Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list |
References
History
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-17T21:09:16.034Z
Reserved: 2023-12-29T16:10:20.367Z
Link: CVE-2024-21665
Updated: 2025-06-17T21:06:56.583Z
Status : Modified
Published: 2024-01-11T01:15:45.413
Modified: 2024-11-21T08:54:49.570
Link: CVE-2024-21665
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA