CVE-2023-32062

MEDIUM

Oroinc Oroplatform < 4.2.6 - Improper Access Control

Title source: rule
STIX 2.1

Description

OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.

Scores

CVSS v3 5.0
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Details

CWE
CWE-284
Status published
Products (2)
oro/calendar-bundle 4.2.0Packagist
oroinc/oroplatform 4.2.0 - 4.2.6
Published Nov 27, 2023
Tracked Since Feb 18, 2026