Логотип exploitDog
bind:CVE-2023-32064
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-32064

Количество 2

Количество 2

nvd логотип

CVE-2023-32064

около 2 лет назад

OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-8gwj-68w6-7v6c

около 2 лет назад

OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-32064

OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1.

CVSS3: 5
0%
Низкий
около 2 лет назад
github логотип
GHSA-8gwj-68w6-7v6c

OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility

CVSS3: 4.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу