Lucene search

K
cveGitHub_MCVE-2024-21665
HistoryJan 11, 2024 - 1:15 a.m.

CVE-2024-21665

2024-01-1101:15:45
CWE-284
GitHub_M
web.nvd.nist.gov
26
pimcore
ecommerce
framework
bundle
cve
2024
21665
security
vulnerability
access control
permissions
patch

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

18.0%

ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not being enforced. This vulnerability has been patched in version 1.0.10.

Affected configurations

Nvd
Vulners
Node
pimcoree-commerce_frameworkRange<1.0.10
VendorProductVersionCPE
pimcoree-commerce_framework*cpe:2.3:a:pimcore:e-commerce_framework:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "pimcore",
    "product": "ecommerce-framework-bundle",
    "versions": [
      {
        "version": "< 1.0.10",
        "status": "affected"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

18.0%

Related for CVE-2024-21665