vendor:
eZ Publish
by:
s4avrd0w
7.5
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: eZ Publish
Affected Version From: 3.5.2006
Affected Version To: 3.9.2004
Patch Exists: YES
Related CWE:
CPE: a:ez_systems:ez_publish:3.5.6
Platforms Tested:
2008
eZ Publish privilege escalation exploit
This is an exploit for a privilege escalation vulnerability in eZ Publish versions >= 3.5.6. The vulnerability allows an attacker to escalate their privileges and gain administrative access to the eZ Publish system. The exploit sends a malicious request to the target server, creating a new admin account with the provided username, password, and email. The new admin account will be activated and registered in the system.
Mitigation:
Upgrade to eZ Publish versions 3.9.5, 3.10.1, or 4.0.1 to resolve the vulnerability.