ezsystems/ezpublish-kernel

ezsystems/ezpublish-kernel

Releases336
Frequency1 week 6 days
Last Release
Stars160
Kernel (Repository, MVC layer, REST) for eZ Platform

CVE History

CVEPublishedCVSS v3CVSS v2
3.7 LOW

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.

9.8 CRITICAL

An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.

6.1 MEDIUM

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file.

5.3 MEDIUM

An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.

7.2 HIGH

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.