Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-02-18T17:49:08

Updated: 2022-02-18T17:49:08

Reserved: 2022-02-18T00:00:00


Link: CVE-2022-25336

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-18T18:15:13.537

Modified: 2023-08-08T14:21:49.707


Link: CVE-2022-25336

JSON object: View

cve-icon Redhat Information

No data.

CWE