CVE-2007-4493
Publication date 23 August 2007
Last updated 17 July 2025
Ubuntu priority
Description
eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.