CVE-2023-48296

Source
https://cve.org/CVERecord?id=CVE-2023-48296
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-48296.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-48296
Aliases
Published
2024-03-25T18:19:43.561Z
Modified
2025-12-12T21:56:09.947282Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
OroPlatform's storefront user can access history and most viewed data from matching back-office user with the same ID
Details

OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. This vulnerability is fixed in 5.1.4.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/48xxx/CVE-2023-48296.json"
}
References

Affected packages

Git / github.com/oroinc/orocommerce

Affected ranges

Type
GIT
Repo
https://github.com/oroinc/orocommerce
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0-alpha.1
1.0.0-alpha.2
1.0.0-alpha.3
1.0.0-alpha.5
1.0.0-beta.1
1.0.0-beta.2

4.*

4.1.0-rc4

5.*

5.0.0-alpha.1
5.1.0
5.1.1
5.1.2
5.1.3

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-48296.json"

Git / github.com/oroinc/platform

Affected ranges

Type
GIT
Repo
https://github.com/oroinc/platform
Events

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-48296.json"