5.8
CVE-2023-32065
- EPSS 0.25%
- Veröffentlicht 28.11.2023 04:15:07
- Zuletzt bearbeitet 21.11.2024 08:02:38
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oroinc ≫ Orocommerce Version >= 4.2.0 <= 4.2.10
Oroinc ≫ Orocommerce Version >= 5.0.0 < 5.0.11
Oroinc ≫ Orocommerce Version >= 5.1.0 < 5.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.475 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
|
| security-advisories@github.com | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.