Back to Database
Status published
Medium
CVE-2023-32065
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
Vulnerability Description
OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-32065
Credits & Attribution
No credits recorded in the NVD database.
More from oroinc
View All →CVE-2023-48296
OroPlatform's storefront user can access history and most viewed data from matching back-office user with the same ID
Medium
4.3
CVE-2023-45824
OroPlatform's pinned entity creation form shows pages of other users
Medium
4.3
CVE-2023-32064
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
Medium
5
CVE-2023-32063
OroCRMCallBundle has incorrect call view page visibility
Medium
5
CVE-2023-32062
OroCalendarBundle has incorrect system calendar events visibility
Medium
5
Affected Vendor
oroinc
View all reports →Affected Software
orocommerce
Vulnerable Versions:
>= 4.2.0, <= 4.2.10, >= 5.0.0, < 5.0.11, >= 5.1.0, < 5.1.1
Timeline
Official Publish:
November 28th, 2023
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N