CVE Vulnerabilities

CVE-2007-4493

Published: Aug 23, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.

Affected Software

NameVendorStart VersionEnd Version
Ez_publishEz*3.8.8 (including)
Ez_publishEz3.9.0 (including)3.9.0 (including)
Ez_publishEz3.9.1 (including)3.9.1 (including)
Ez_publishEz3.9.2 (including)3.9.2 (including)
EzpublishUbuntudapper*
EzpublishUbuntuedgy*
EzpublishUbuntufeisty*
EzpublishUbuntugutsy*

References