Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1251 | Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced. |
Github GHSA |
GHSA-x8xx-x82q-42q3 | Exposure of Resource to Wrong Sphere in ezsystems/ezplatform-kernel |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T04:36:06.920Z
Reserved: 2022-02-18T00:00:00
Link: CVE-2022-25336
No data.
Status : Modified
Published: 2022-02-18T18:15:13.537
Modified: 2024-11-21T06:52:01.713
Link: CVE-2022-25336
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA