CVE-2023-32063

Publication date

2023-11-28 03:30:22

Family

GitHub_M

State

PUBLISHED

Description

OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.