Miggo Logo

CVE-2023-48296:
Storefront user can access history and most viewed data from matching back-office user with the same ID

4.3

CVSS Score
3.1

Basic Information

EPSS Score
0.3877%
Published
3/25/2024
Updated
3/25/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
oro/customer-portalcomposer>= 4.1.0, <= 4.1.13
oro/customer-portalcomposer>= 4.2.0, <= 4.2.10
oro/customer-portalcomposer>= 5.0.0, <= 5.0.11
oro/customer-portalcomposer>= 5.1.0, <= 5.1.35.1.4

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided commit diff and vulnerability description show a mismatch in context. The vulnerability describes an authorization issue where storefront users access back-office user data through ID matching, while the commit focuses on UI element visibility (multi-file/image attribute display). The patched files modify form rendering logic and add event listeners to control field visibility, but none of these changes directly address user authorization checks or data exposure between user types. The core vulnerability likely exists in user data retrieval/authorization logic that isn't reflected in the provided code changes. Without evidence of functions handling user session context or data access authorization in the provided diff, we cannot confidently identify specific vulnerable functions from the given information.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

### Imp**t N*vi**tion *istory, most vi*w** *n* **vorit* n*vi**tion it*ms *r* r*turn** to stor**ront us*r in JSON n*vi**tion r*spons* i* I* o* stor**ront us*r m*t***s I* o* ***k-o**i** us*r.

Reasoning

T** provi*** *ommit *i** *n* vuln*r**ility **s*ription s*ow * mism*t** in *ont*xt. T** vuln*r**ility **s*ri**s *n *ut*oriz*tion issu* w**r* stor**ront us*rs ****ss ***k-o**i** us*r **t* t*rou** I* m*t**in*, w*il* t** *ommit *o*us*s on UI *l*m*nt visi