« Volver al listado

CVE-2007-4493

Estado: ModificadaAlta (10)—

eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4493",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-08-23T01:17:00.000",
  "references": [
    {
      "url": "http://ez.no/community/news/ez_publish_security_fixes_3_9_3_and_3_8_9",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ez.no/download/ez_publish/changelogs/ez_publish_3_8/changelog_3_8_8_to_3_8_9",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ez.no/download/ez_publish/changelogs/ez_publish_3_9/changelog_3_9_2_to_3_9_3",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/40324",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/26686",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/25539",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ez.no/community/news/ez_publish_security_fixes_3_9_3_and_3_8_9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://ez.no/download/ez_publish/changelogs/ez_publish_3_8/changelog_3_8_8_to_3_8_9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://ez.no/download/ez_publish/changelogs/ez_publish_3_9/changelog_3_9_2_to_3_9_3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/40324",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/26686",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/25539",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module."
    },
    {
      "lang": "es",
      "value": "eZ publish anterior a 3.8.9, y 3.9 anterior a 3.9.3, no comprueba adecuadamente los permisos en las vistas de los módulos que carecen de una función de política, lo cual tiene impacto y vectores de ataque desconocidos, como ha sido demostrado por una vulnerabilidad en la funcionalidad de descuentos del módulo de compra."
    }
  ],
  "lastModified": "2026-06-16T22:44:12.133",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "188CAEF6-A825-4362-86F5-929E2F595010",
              "versionEndIncluding": "3.8.8"
            },
            {
              "criteria": "cpe:2.3:a:ez:ez_publish:3.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C76B152B-FE9D-47A5-B011-066814F72953"
            },
            {
              "criteria": "cpe:2.3:a:ez:ez_publish:3.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77519B1C-CB4E-4239-81AA-5C1CDE81A45B"
            },
            {
              "criteria": "cpe:2.3:a:ez:ez_publish:3.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4F62153-7A64-44C1-ABE7-68D4628DEE38"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}