The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to conduct spam attacks.
| Software | From | Fixed in |
|---|---|---|
| ez / ez_publish | - | 3.8.8.x |
| ez / ez_publish | 3.9.0 | 3.9.0.x |
| ez / ez_publish | 3.9.2 | 3.9.2.x |
| ez / ez_publish | 3.9.1 | 3.9.1.x |