Security Advisory

CVE-2006-7218

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-07-06 19:00:00
Last updated 2024-09-16 20:43:19
Assigner mitre
State PUBLISHED

Description

eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.