CVE-2023-32065

OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oroinc:orocommerce:*:*:*:*:*:*:*:*
cpe:2.3:a:oroinc:orocommerce:*:*:*:*:*:*:*:*
cpe:2.3:a:oroinc:orocommerce:*:*:*:*:*:*:*:*

History

01 Dec 2023, 22:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.8
References () https://github.com/oroinc/orocommerce/security/advisories/GHSA-88g2-xgh9-4ph2 - () https://github.com/oroinc/orocommerce/security/advisories/GHSA-88g2-xgh9-4ph2 - Vendor Advisory
First Time Oroinc
Oroinc orocommerce
CPE cpe:2.3:a:oroinc:orocommerce:*:*:*:*:*:*:*:*

28 Nov 2023, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-28 04:15

Updated : 2023-12-01 22:00


NVD link : CVE-2023-32065

Mitre link : CVE-2023-32065


JSON object : View

Products Affected

oroinc

  • orocommerce
CWE
CWE-284

Improper Access Control