CVE-2023-32063: Oroinc Client Relationship Management

Medium severity, CVSS 5.0. EPSS: 0.5% chance of exploitation in the next 30 days.

OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.

Affected products

  • Oroinc Client Relationship Management: from 4.2.0, up to and including 4.2.5; from 5.0.0, before 5.0.4 (fixed in 5.0.4); from 5.1.0, before 5.1.1 (fixed in 5.1.1)

Published 2023-11-28. Last modified 2026-06-17.