PT-2024-19007 · Pimcore · Pimcore Ecommerce Framework Bundle

Wisconaut

·

Published

2024-01-10

·

Updated

2024-01-17

·

CVE-2024-21665

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pimcore Ecommerce Framework Bundle versions prior to 1.0.10
Description The issue allows an authenticated and unauthorized user to access the back-office orders list and query over the information returned due to a lack of enforced access control and permissions. This can be achieved by accessing the admin/ecommerceframework/admin-order/list endpoint, which does not seem to validate user permissions. As a result, an unauthorized user can access back-office orders without proper authorization.
Recommendations For versions prior to 1.0.10, update to version 1.0.10 to resolve the issue. As a temporary workaround, consider restricting access to the admin/ecommerceframework/admin-order/list endpoint until the update is applied. Additionally, review and ensure that all users have appropriate permissions and access controls in place to prevent unauthorized access to sensitive data.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-21665
GHSA-CX99-25HR-5JXF

Affected Products

Pimcore Ecommerce Framework Bundle