CVE Vulnerabilities

CVE-2007-4493

Published: Aug 23, 2007 | Modified: Jul 27, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.

Affected Software

Name Vendor Start Version End Version
Ez_publish Ez * 3.8.8 (including)
Ez_publish Ez 3.9.0 (including) 3.9.0 (including)
Ez_publish Ez 3.9.1 (including) 3.9.1 (including)
Ez_publish Ez 3.9.2 (including) 3.9.2 (including)

References