Описание
OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. This vulnerability is fixed in 5.1.4.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.1.0 (включая) до 5.1.4 (исключая)
cpe:2.3:a:oroinc:oroplatform:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00229
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 4.3
github
почти 2 года назад
Storefront user can access history and most viewed data from matching back-office user with the same ID
EPSS
Процентиль: 45%
0.00229
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-200
NVD-CWE-noinfo