OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages of other users by pageId hash. This vulnerability is fixed in 5.1.4.
References
Configurations
History
10 Mar 2025, 14:59
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:oroinc:oroplatform:*:*:*:*:*:*:*:* | |
First Time |
Oroinc oroplatform
Oroinc |
|
CWE | NVD-CWE-noinfo | |
References | () https://github.com/oroinc/platform/commit/cf94df7595afca052796e26b299d2ce031e289cd - Product | |
References | () https://github.com/oroinc/platform/security/advisories/GHSA-vxq2-p937-3px3 - Patch, Vendor Advisory |
21 Nov 2024, 08:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/oroinc/platform/commit/cf94df7595afca052796e26b299d2ce031e289cd - | |
References | () https://github.com/oroinc/platform/security/advisories/GHSA-vxq2-p937-3px3 - |
26 Mar 2024, 12:55
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Mar 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-25 19:15
Updated : 2025-03-10 14:59
NVD link : CVE-2023-45824
Mitre link : CVE-2023-45824
CVE.ORG link : CVE-2023-45824
JSON object : View
Products Affected
oroinc
- oroplatform
CWE