4.3
CVE-2023-45824
- EPSS 0.24%
- Veröffentlicht 25.03.2024 19:15:57
- Zuletzt bearbeitet 10.03.2025 15:21:07
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages of other users by pageId hash. This vulnerability is fixed in 5.1.4.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oroinc ≫ Oroplatform Version >= 4.2.0 < 5.1.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.472 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| security-advisories@github.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.