CVE-2022-25336
EUVD-2022-125118.02.2022, 18:15
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibexa | ez_platform_kernel | 1.3.0 ≤ 𝑥 < 1.3.12 |
| ibexa | ez_platform_kernel | 7.5.0 ≤ 𝑥 < 7.5.26 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration