CVE-2006-7219
eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to create a draft in an unauthorized language by editing an archived version of an object, and then using Manage…
Does this matter?
Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.
Description
eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to create a draft in an unauthorized language by editing an archived version of an object, and then using Manage Versions to copy this version to a new draft.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ez/ez publish
- Source
- cve@mitre.org
References
- http://ez.no/download/ez_publish/changelogs/ez_publish_3_8/changelog_3_8_4_to_3_8_5Patch
- http://ez.no/download/ez_publish/changelogs/ez_publish_3_9/changelog_3_8_0_to_3_9_0
- http://issues.ez.no/8795
- http://ez.no/download/ez_publish/changelogs/ez_publish_3_8/changelog_3_8_4_to_3_8_5Patch
- http://ez.no/download/ez_publish/changelogs/ez_publish_3_9/changelog_3_8_0_to_3_9_0
- http://issues.ez.no/8795
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.