CVE-2023-32062: Oroinc Oroplatform
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
Affected products
- Oroinc Oroplatform: from 4.2.0, up to and including 4.2.6; from 5.0.0, before 5.0.7 (fixed in 5.0.7); from 5.1.0, before 5.1.1 (fixed in 5.1.1)
Published 2023-11-27. Last modified 2026-06-17.