ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0339 | ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10. |
Github GHSA |
GHSA-cx99-25hr-5jxf | Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-17T21:09:16.034Z
Reserved: 2023-12-29T16:10:20.367Z
Link: CVE-2024-21665
Updated: 2025-06-17T21:06:56.583Z
Status : Modified
Published: 2024-01-11T01:15:45.413
Modified: 2024-11-21T08:54:49.570
Link: CVE-2024-21665
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA