PT-2012-5171 · Ez Systems · Ez Publish+1
Publicado
2012-07-25
·
Atualizado
2019-07-30
·
CVE-2012-4053
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eZ Publish versions 4.1 through 4.6
Description
A cross-site request forgery (CSRF) issue exists in the eZOE flash player component, allowing remote attackers to hijack the authentication of victims via unknown vectors.
Recommendations
For versions 4.1 through 4.6, update to a version that includes a fix for this issue to prevent authentication hijacking.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ez Publish
Ezoe