VulnerabilityModified
CVE-2008-0701
ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.
MEDIUM 5.0EPSS 1.19%
Does this matter?
Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.
Description
ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- magnolia/ce
- Source
- cve@mitre.org
References
- http://jira.magnolia.info/browse/MAGNOLIA-2021
- http://secunia.com/advisories/28745Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=573088
- http://www.securityfocus.com/bid/27608
- http://jira.magnolia.info/browse/MAGNOLIA-2021
- http://secunia.com/advisories/28745Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=573088
- http://www.securityfocus.com/bid/27608
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.