pimcore/ecommerce-framework-bundle
Pimcore Ecommerce Bundle
Activity
- Latest release
- 9mo ago
- Total releases
- 30
- Cadence
- ~23 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- GPL-3.0
- First release
- Apr 13, 2023
| Version | Released | |
|---|---|---|
v1.3.5
patch
deprecated
|
v1.3.5
patch
deprecated
Dependencies (6)
Changelog
Compare changes
|
|
v1.3.4
patch
| ||
v1.3.3
patch
| ||
v1.3.2
patch
| ||
v1.3.1
patch
| ||
v1.3.0
minor
| ||
v1.2.3
patch
|
v1.2.3
patch
Dependencies (6)
Changelog
Compare changes
|
|
v1.2.2
patch
| ||
v1.2.1
patch
| ||
v1.2.0
minor
|
v1.2.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
v1.1.1
patch
| ||
v1.0.14
patch
|
v1.0.14
patch
Dependencies (7)
Changelog
Compare changes
|
|
v1.0.13
patch
| ||
v1.1.0
minor
|
v1.1.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
v1.0.12
patch
|
v1.0.12
patch
Dependencies (6)
Changelog
Compare changes
|
|
v1.0.11
patch
| ||
v1.0.10
patch
| ||
v1.0.9
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.8
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.7
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.6
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.5
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.4
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.3
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.2
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.1
patch
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.0
initial
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.0-RC2
pre
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.0-RC1
pre
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v1.0.0-BETA1
pre
1 CVE
CVE-2024-21665
GHSA-cx99-25hr-5jxf
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
SummaryAn authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. DetailsPermissions do not seem to be enforced when reaching the Note : Testing this vulnerability requires a fully configured ecommerce website, but it looks vulnerable as when requesting the endpoint the data seem returned (and when looking at the source code nothing seems to validate the permissions on the specified endpoint). PoCIn order to reproduce the issue, the following steps can be followed :
ImpactAn unauthorized user can access back-office orders without being authorized to. Affected versions
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
+ 1 more Show less
v1.0.9
Fixed in
1.0.10
References
Updated Sep 10, 2026 · Source: OSV.dev |