PT-2024-13577 · Unknown · Oroplatform

Khrysev

·

Published

2024-03-25

·

Updated

2024-03-26

·

CVE-2023-48296

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OroPlatform versions prior to 5.1.4
Description The issue concerns OroPlatform, a PHP Business Application Platform (BAP), where navigation history, most viewed, and favorite navigation items are returned to a storefront user in a JSON navigation response if the ID of the storefront user matches the ID of a back-office user.
Recommendations For versions prior to 5.1.4, update to version 5.1.4 to resolve the issue. As a temporary workaround, consider restricting access to sensitive navigation items until the update is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-48296
GHSA-V7PX-46V9-5QWP

Affected Products

Oroplatform