CVE-2024-21665

MEDIUM

Pimcore E-Commerce Framework < 1.0.10 - Authenticated Improper Access Control in Admin Order List

Title source: llm
STIX 2.1

Description

ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10.

Scores

CVSS v3 4.3
EPSS 0.0049
EPSS Percentile 38.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
pimcore/e-commerce_framework < 1.0.10
pimcore/ecommerce-framework-bundle 0 - 1.0.10Packagist
Published Jan 11, 2024
Tracked Since Feb 18, 2026