CVE-2023-32062

MEDIUM

OroPlatform 4.2.0-4.2.5 - Improper Access Control in Calendar Event Handling

Title source: llm
STIX 2.1

Description

OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.

Scores

CVSS v3 5.0
EPSS 0.0054
EPSS Percentile 41.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Details

CWE
CWE-284
Status published
Products (2)
oro/calendar-bundle 4.2.0Packagist
oroinc/oroplatform 4.2.0 - 4.2.6
Published Nov 27, 2023
Tracked Since Feb 18, 2026