Ezsystems Ezpublish-Legacy vulnerabilities
2 known vulnerabilities affecting ezsystems/ezpublish-legacy.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-10806CRITICAL≥ 0, < 5.4.14.1≥ 2017, < 2017.12.7.2+1 more2022-05-24
CVE-2020-10806 [CRITICAL] eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution.
ghsaosv
CVE-2017-1000431MEDIUM≥ 5.4.0, < 5.4.10≥ 5.3.0, < 5.3.12.12022-05-14
CVE-2017-1000431 [MEDIUM] CWE-79 eZ Publish Cross-site Scripting (XSS) vulnerability
eZ Publish Cross-site Scripting (XSS) vulnerability
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12.0 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
ghsaosv