PT-2012-5171 · Ez Systems · Ez Publish+1
Published
2012-07-25
·
Updated
2019-07-30
·
CVE-2012-4053
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eZ Publish versions 4.1 through 4.6
Description
A cross-site request forgery (CSRF) issue exists in the eZOE flash player component, allowing remote attackers to hijack the authentication of victims via unknown vectors.
Recommendations
For versions 4.1 through 4.6, update to a version that includes a fix for this issue to prevent authentication hijacking.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ez Publish
Ezoe