CVE-2007-4493

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/08/2007
Last modified:
09/04/2025

Description

eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:* 3.8.8 (including)
cpe:2.3:a:ez:ez_publish:3.9.0:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.9.1:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.9.2:*:*:*:*:*:*:*