PT-2007-1495 · Ez Systems · Ez Publish
Publicado
2007-07-06
·
Atualizado
2015-07-28
·
CVE-2006-7219
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
eZ publish versions prior to 3.8.5
Description
The issue allows remote authenticated users to bypass permission checks for editing in a specific language. This can be achieved by editing an archived version of an object and then using Manage Versions to copy this version to a new draft, thereby creating a draft in an unauthorized language.
Recommendations
For versions prior to 3.8.5, update to version 3.8.5 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ez Publish