OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
Vulnerability Description
OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-32064
Credits & Attribution
No credits recorded in the NVD database.
More from oroinc
View All →Affected Vendor
oroinc
View all reports →