Описание
eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit data submitted by arbitrary anonymous users.
Ссылки
- PatchVendor Advisory
- Broken Link
- PatchVendor Advisory
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия от 3.5.0 (включая) до 3.7 (включая)
cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00201
Низкий
5 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
ubuntu
больше 19 лет назад
eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit data submitted by arbitrary anonymous users.
debian
больше 19 лет назад
eZ publish 3.5 through 3.7 before 20050608 requires both edit and crea ...
github
больше 3 лет назад
eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit data submitted by arbitrary anonymous users.
EPSS
Процентиль: 42%
0.00201
Низкий
5 Medium
CVSS2
Дефекты
CWE-264