Vulnerabilities > CVE-2023-45824 - Unspecified vulnerability in Oroinc Oroplatform
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages of other users by pageId hash. This vulnerability is fixed in 5.1.4.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- https://github.com/oroinc/platform/commit/cf94df7595afca052796e26b299d2ce031e289cd
- https://github.com/oroinc/platform/commit/cf94df7595afca052796e26b299d2ce031e289cd
- https://github.com/oroinc/platform/security/advisories/GHSA-vxq2-p937-3px3
- https://github.com/oroinc/platform/security/advisories/GHSA-vxq2-p937-3px3