PT-2024-40535 · Ez Systems · Ez-Support-Tools

Published

2024-05-15

·

Updated

2024-05-15

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: ezsystems/ez-support-tools version 2.2
Description: The issue allows a user with insufficient permissions to access system information tabs by directly typing in the link, despite the link not being shown in the menu. Normally, the "Setup / System info" policy should be required for access, but currently, only a backend login is needed. This means any editor can view core system information, including phpinfo() output.
Recommendations: For ezsystems/ez-support-tools version 2.2, ensure that the access policy is correctly verified to restrict access to the system information tabs, requiring the "Setup / System info" policy as intended.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-XMP3-7745-G4VJ

Affected Products

Ez-Support-Tools