VYPR

Packagist (Composer) package

ezsystems/ezpublish-legacy

pkg:composer/ezsystems/ezpublish-legacy

Vulnerabilities (2)

  • CVE-2020-10806Mar 22, 2020
    affected < 5.4.14.1fixed 5.4.14.1

    eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permit

  • CVE-2017-1000431Jan 2, 2018
    affected >= 5.4.0, < 5.4.10fixed 5.4.10

    eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.