Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to create a draft in an unauthorized language by editing an archived version of an object, and then using Manage Versions to copy this version to a new draft.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
eZ publish 远程验证漏洞
Vulnerability Description
eZ publish 3.8.5版本之前的版本没有适当地实施在特定语言中进行编辑的许可,这会允许远程验证用户通过编辑一个对象的存档文件来创建一个草稿文件,并运行管理版本以把该版本拷贝到一个新的草稿文件中。
CVSS Information
N/A
Vulnerability Type
N/A