Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-02-18T17:49:08
Updated: 2024-08-03T04:36:06.920Z
Reserved: 2022-02-18T00:00:00
Link: CVE-2022-25336
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-18T18:15:13.537
Modified: 2024-11-21T06:52:01.713
Link: CVE-2022-25336
Redhat
No data.