5
CVE-2023-32064
- EPSS 0.1%
- Veröffentlicht 28.11.2023 04:15:07
- Zuletzt bearbeitet 21.11.2024 08:02:38
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oroinc ≫ Orocommerce Version >= 4.2.0 <= 4.2.8
Oroinc ≫ Orocommerce Version >= 5.0.0 < 5.0.11
Oroinc ≫ Orocommerce Version >= 5.1.0 < 5.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.284 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| security-advisories@github.com | 5 | 3.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.