CVE-2023-48296

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
25/03/2024
Last modified:
10/03/2025

Description

OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. This vulnerability is fixed in 5.1.4.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oroinc:oroplatform:*:*:*:*:*:*:*:* 4.1.0 (including) 5.1.4 (excluding)