Medium severity4.3NVD Advisory· Published Mar 25, 2024· Updated Jun 17, 2026
CVE-2023-45824
CVE-2023-45824
Description
OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages of other users by pageId hash. This vulnerability is fixed in 5.1.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
oro/platformPackagist | >= 5.1.0, < 5.1.4 | 5.1.4 |
oro/platformPackagist | >= 5.0.0, <= 5.0.12 | — |
oro/platformPackagist | >= 4.2.0, <= 4.2.10 | — |
Affected products
3- oroinc/platformv5Range: >=4.2.0, <=4.2.10
Patches
Vulnerability mechanics
References
4- github.com/oroinc/platform/security/advisories/GHSA-vxq2-p937-3px3nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-vxq2-p937-3px3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-45824ghsaADVISORY
- github.com/oroinc/platform/commit/cf94df7595afca052796e26b299d2ce031e289cdnvdProductWEB
News mentions
0No linked articles in our index yet.