Back to Database
Status published
Medium
CVE-2023-32062
OroCalendarBundle has incorrect system calendar events visibility
Vulnerability Description
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-32062
Credits & Attribution
No credits recorded in the NVD database.
References
More from oroinc
View All →CVE-2023-48296
OroPlatform's storefront user can access history and most viewed data from matching back-office user with the same ID
Medium
4.3
CVE-2023-45824
OroPlatform's pinned entity creation form shows pages of other users
Medium
4.3
CVE-2023-32065
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
Medium
5.8
CVE-2023-32064
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
Medium
5
CVE-2023-32063
OroCRMCallBundle has incorrect call view page visibility
Medium
5
Affected Vendor
oroinc
View all reports →Affected Software
crm
Vulnerable Versions:
>= 4.2.0, <= 4.2.6, >= 5.0.0, <= 5.0.6, >= 5.1.0, < 5.1.1
Timeline
Official Publish:
November 27th, 2023
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N