← Back

CVE-2006-7219

nvd nist
Published: Jul 6, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to create a draft in an unauthorized language by editing an archived version of an object, and then using Manage Versions to copy this version to a new draft.

Affected (1)

Products: Ez: Ez Publish
1 product
Ez Publish
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.8.4

Related CWEs

Timeline

No history available yet.