PT-2024-19007 · Pimcore · Pimcore Ecommerce Framework Bundle
Wisconaut
·
Published
2024-01-10
·
Updated
2024-01-17
·
CVE-2024-21665
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pimcore Ecommerce Framework Bundle versions prior to 1.0.10
Description
The issue allows an authenticated and unauthorized user to access the back-office orders list and query over the information returned due to a lack of enforced access control and permissions. This can be achieved by accessing the
admin/ecommerceframework/admin-order/list endpoint, which does not seem to validate user permissions. As a result, an unauthorized user can access back-office orders without proper authorization.Recommendations
For versions prior to 1.0.10, update to version 1.0.10 to resolve the issue. As a temporary workaround, consider restricting access to the
admin/ecommerceframework/admin-order/list endpoint until the update is applied. Additionally, review and ensure that all users have appropriate permissions and access controls in place to prevent unauthorized access to sensitive data.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pimcore Ecommerce Framework Bundle