Total vulnerabilities in the database
eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.
Software | From | Fixed in |
---|---|---|
ez / ez_publish | - | 3.8.8.x |
ez / ez_publish | 3.9.0 | 3.9.0.x |
ez / ez_publish | 3.9.2 | 3.9.2.x |
ez / ez_publish | 3.9.1 | 3.9.1.x |