CVE-2023-45824

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
25/03/2024
Last modified:
10/03/2025

Description

OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages of other users by pageId hash. This vulnerability is fixed in 5.1.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oroinc:oroplatform:*:*:*:*:*:*:*:* 4.2.0 (including) 5.1.4 (excluding)