Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qj7-c8cr-rw2h

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

EPSS

Процентиль: 56%
0.00333
Низкий

Связанные уязвимости

ubuntu
больше 20 лет назад

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

nvd
больше 20 лет назад

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

debian
больше 20 лет назад

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, ...

EPSS

Процентиль: 56%
0.00333
Низкий