Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://github.com/brookinsconsulting/bccie/commit/d11811baccf265ff567dddca03cac70b65838a4f | third party advisory patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/92129 | vdb entry third party advisory |
https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2014-004/?fid=3853 | third party advisory |