Security Advisory
CVE-2023-32063
5
MEDIUM
Vulnerability Description
OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.
Published Date
November 28, 2023
Official Source
NIST NVD Advisory