VYPR
Medium severity5.0NVD Advisory· Published Nov 27, 2023· Updated Jun 17, 2026

CVE-2023-32062

CVE-2023-32062

Description

OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
oro/calendar-bundlePackagist
>= 4.2.0, <= 4.2.6
oro/calendar-bundlePackagist
>= 5.0.0, < 5.0.75.0.7
oro/calendar-bundlePackagist
>= 5.1.0, < 5.1.15.1.1

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.