QID 996068
Date Published: 2023-11-28
QID 996068: PHP (Composer) Security Update for oro/customer-portal (GHSA-8gwj-68w6-7v6c)
Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-8gwj-68w6-7v6c for updates and patch information.
Vendor References
- GHSA-8gwj-68w6-7v6c -
github.com/advisories/GHSA-8gwj-68w6-7v6c
CVEs related to QID 996068
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8gwj-68w6-7v6c | oro/customer-portal |
|