oro/customer-portal
OroCommerce package with customer portal and non authenticated visitor website base features.
Activity
- Latest release
- Jun 11, 2026
- Total releases
- 171
- Cadence
- ~22 days
- Last 12 months
- 13
Reach
- Stars
- 14
Details
- License
- unknown
- First release
- Mar 28, 2017
| Version | Released | |
|---|---|---|
6.1.10
patch
| ||
7.0.3
patch
| ||
7.0.2
patch
| ||
7.0.1
patch
| ||
6.1.9
patch
| ||
7.0.0
major
| ||
6.1.8
patch
| ||
7.0.0-rc
pre
| ||
6.1.7
patch
| ||
6.1.6
patch
| ||
6.0.10
patch
| ||
6.1.5
patch
| ||
6.1.5-rc1
pre
| ||
6.1.4
patch
| ||
6.1.3
patch
| ||
6.0.9
patch
| ||
6.1.2
patch
| ||
6.1.1
patch
| ||
6.1.0
minor
| ||
6.0.8
patch
| ||
6.1.0-rc.3
pre
| ||
6.0.7
patch
| ||
6.1.0-rc
pre
| ||
6.0.6
patch
| ||
6.0.5
patch
| ||
6.0.4
patch
| ||
6.0.3
patch
| ||
6.0.2
patch
| ||
5.1.8
patch
| ||
6.0.1
patch
| ||
5.1.7
patch
| ||
6.0.0
major
| ||
6.0.0-rc
pre
| ||
5.1.6
patch
| ||
5.1.5
patch
| ||
6.0.0-beta.1
pre
| ||
5.1.4
patch
| ||
5.1.3
patch
1 CVE
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev | ||
5.1.2
patch
1 CVE
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev | ||
5.1.1
patch
1 CVE
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev | ||
5.0.11
patch
1 CVE
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev | ||
5.1.0
minor
2 CVEs
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev
CVE-2023-32064
GHSA-8gwj-68w6-7v6c
Nov 27, 2023
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. Affected versions
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
+ 9 more Show less
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
5.0.10
patch
2 CVEs
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev
CVE-2023-32064
GHSA-8gwj-68w6-7v6c
Nov 27, 2023
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. Affected versions
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
+ 9 more Show less
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
5.1.0-rc.2
pre
| ||
5.0.9
patch
2 CVEs
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev
CVE-2023-32064
GHSA-8gwj-68w6-7v6c
Nov 27, 2023
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. Affected versions
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
+ 9 more Show less
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
5.1.0-rc.1
pre
| ||
5.0.8
patch
2 CVEs
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev
CVE-2023-32064
GHSA-8gwj-68w6-7v6c
Nov 27, 2023
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. Affected versions
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
+ 9 more Show less
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev | ||
5.1.0-beta.2
pre
| ||
5.1.0-beta.1
pre
| ||
5.0.7
patch
2 CVEs
CVE-2023-48296
GHSA-v7px-46v9-5qwp
Mar 25, 2024
Storefront user can access history and most viewed data from matching back-office user with the same ID
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactNavigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user. Affected versions
4.1.0
4.1.1
4.1.1-rc
4.1.1-rc2
4.1.10
4.1.11
4.1.12
4.1.13
4.1.2
4.1.3
4.1.4
4.1.5
+ 29 more Show less
4.1.6
4.1.7
4.1.8
4.1.9
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
5.0.11
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Mar 25, 2024 · Source: OSV.dev
CVE-2023-32064
GHSA-8gwj-68w6-7v6c
Nov 27, 2023
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. Affected versions
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
5.0.0
5.0.1
5.0.10
+ 9 more Show less
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
Fixed in
5.0.11
5.1.1
References Updated Feb 16, 2024 · Source: OSV.dev |