ZeroHour

CVE-2023-32063

CVSS 3.1
5.0 medium
EPSS
<1%p44
Published
()
Modified
Description

OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.

Vendors
oroinc
Products
client relationship management
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.