Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
| Software | From | Fixed in |
|---|---|---|
| ez / ez_publish | 4.2.0 | 4.2.0.x |
| ez / ez_publish | 4.1.0 | 4.1.0.x |
| ez / ez_publish | 4.3.0 | 4.3.0.x |