CVE-2023-48296

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-48296
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-48296.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-48296
Aliases
Published
2024-03-25T19:15:57Z
Modified
2024-10-08T03:55:02.390722Z
Summary
[none]
Details

OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. This vulnerability is fixed in 5.1.4.

References

Affected packages

Git / github.com/oroinc/orocommerce

Affected ranges

Type
GIT
Repo
https://github.com/oroinc/orocommerce
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0-alpha.1
1.0.0-alpha.2
1.0.0-alpha.3
1.0.0-alpha.5
1.0.0-beta.1
1.0.0-beta.2

4.*

4.1.0-rc4

5.*

5.0.0-alpha.1
5.1.0
5.1.1
5.1.2
5.1.3