CVE-2024-21665

ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10.
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2024-01-11 01:15

Updated : 2024-01-11 13:57


NVD link : CVE-2024-21665

Mitre link : CVE-2024-21665


JSON object : View

Products Affected

No product.

CWE

No CWE.