CVE-2007-4494
Publication date 23 August 2007
Last updated 17 July 2025
Ubuntu priority
Description
The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to conduct spam attacks.