CVE-2023-32063 - CERT CVE
ID CVE-2023-32063
Sažetak OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.
Reference
CVSS
Base: 5.0
Impact: 1.4
Exploitability:3.1
Pristup
VektorSloženostAutentikacija
NETWORK LOW -
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Zadnje važnije ažuriranje 01-12-2023 - 21:46
Objavljeno 28-11-2023 - 04:15