PT-2023-23577 · Oro · Orocalendarbundle

Khrysev

·

Published

2023-11-27

·

Updated

2023-12-01

·

CVE-2023-32063

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OroCalendarBundle versions prior to 5.0.4 OroCalendarBundle versions prior to 5.1.1
Description The issue allows back-office users to access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This is related to the Calendar feature and functionality in Oro applications.
Recommendations For OroCalendarBundle versions prior to 5.0.4, update to version 5.0.4 or later to resolve the issue. For OroCalendarBundle versions prior to 5.1.1, update to version 5.1.1 or later to resolve the issue.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-32063
GHSA-897W-JV7J-6R7G

Affected Products

Orocalendarbundle