OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32062.json",
"cwe_ids": [
"CWE-284"
],
"cna_assigner": "GitHub_M"
}{
"versions": [
{
"introduced": "4.2.0"
},
{
"last_affected": "4.2.6"
}
]
}{
"versions": [
{
"introduced": "4.2.0"
},
{
"last_affected": "4.2.6"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.0.7"
},
{
"introduced": "5.1.0"
},
{
"fixed": "5.1.1"
}
]
}