PT-2023-23578 · Unknown · Orocommerce

Khrysev

·

Published

2023-11-27

·

Updated

2023-12-01

·

CVE-2023-32064

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OroCommerce versions prior to 5.0.11 OroCommerce versions prior to 5.1.1
Description The issue allows back-office users to access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks.
Recommendations For versions prior to 5.0.11, update to version 5.0.11 or later to resolve the issue. For versions prior to 5.1.1, update to version 5.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Customer and Customer User menus until a patch is applied.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-32064
GHSA-8GWJ-68W6-7V6C

Affected Products

Orocommerce