OroCalendarBundle enables a Calendar... CVE-2023-32063

- AV AC AU C I A
发布: 2023-11-28
修订: 2023-12-01

OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.

0%
暂无可用Exp或PoC
当前有3条受影响产品信息