← Back

CVE-2007-4493

nvd nist
Published: Aug 23, 2007Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.

Affected (4)

Products: Ez: Ez Publish
1 product
Ez Publish
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ez
Up to 3.8.8
Version 3.9.0
Version 3.9.1
Version 3.9.2

Timeline

No history available yet.