5
CVSSv3

CVE-2023-32063

Published: 28/11/2023 Updated: 01/12/2023
CVSS v3 Base Score: 5 | Impact Score: 1.4 | Exploitability Score: 3.1
VMScore: 0

Vulnerability Summary

OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.

Vulnerable Product Search on Vulmon Subscribe to Product

oroinc client relationship management