Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-x2xm-p6vq-482g: OroCalendarBundle has incorrect system calendar events visibility

OroPlatform is a package that assist system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks.

ghsa
#git

OroCalendarBundle has incorrect system calendar events visibility

Moderate severity GitHub Reviewed Published Nov 27, 2023 in oroinc/crm • Updated Nov 27, 2023

Related news

CVE-2023-32062: Incorrect system calendar events visibility

OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.