Количество 2
Количество 2
CVE-2023-32064
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1.
GHSA-8gwj-68w6-7v6c
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-32064 OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1. | CVSS3: 5 | 0% Низкий | около 2 лет назад | |
GHSA-8gwj-68w6-7v6c OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility | CVSS3: 4.3 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу