OroCRMCallBundle是Oro公司的一个插件包。 OroCRMCallBundle存在访问控制错误漏洞,该漏洞源于安全检查不足,导致攻击者可以绕过访问控制列表(ACL)的安全限制从而访问任何事件中的信息。受影响的产品版本:OroCRMCallBundle 4.2.0至4.2.5版本,5.0.0至5.0.3版本,5.1.0至5.1.1之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-32065 | 5.8 MEDIUM | OroCommerce get-totals-for-checkout API endpoint returns unwanted data |
| CVE-2023-32064 | 5.0 MEDIUM | OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages vis |
No comments yet