{"id":"GHSA-39j2-4p9j-5w4j","summary":"Ez Platform Object Injection in legacy shop module","details":"This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity.","modified":"2024-11-29T05:26:35.611726Z","published":"2024-05-15T21:32:29Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-15T21:32:29Z"},"references":[{"type":"WEB","url":"https://ezplatform.com/security-advisories/ibexa-sa-2020-006-object-injection-in-legacy-shop-module"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/ezpublish-legacy/2020-10-05-1.yaml"},{"type":"PACKAGE","url":"https://github.com/ezsystems/ezpublish-legacy"}],"affected":[{"package":{"name":"ezsystems/ezpublish-legacy","ecosystem":"Packagist","purl":"pkg:composer/ezsystems/ezpublish-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2019.3.0"},{"fixed":"2019.3.5.1"}]}],"versions":["v2019.03.0","v2019.03.1","v2019.03.2","v2019.03.3","v2019.03.4","v2019.03.4.2","v2019.03.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-39j2-4p9j-5w4j/GHSA-39j2-4p9j-5w4j.json"}},{"package":{"name":"ezsystems/ezpublish-legacy","ecosystem":"Packagist","purl":"pkg:composer/ezsystems/ezpublish-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2017.12.0"},{"fixed":"2017.12.7.3"}]}],"versions":["v2017.12.0","v2017.12.1","v2017.12.1.1","v2017.12.2","v2017.12.2.1","v2017.12.2.2","v2017.12.3","v2017.12.3.1","v2017.12.3.2","v2017.12.4","v2017.12.4.1","v2017.12.4.2","v2017.12.4.3","v2017.12.5","v2017.12.6","v2017.12.7","v2017.12.7.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-39j2-4p9j-5w4j/GHSA-39j2-4p9j-5w4j.json"}},{"package":{"name":"ezsystems/ezpublish-legacy","ecosystem":"Packagist","purl":"pkg:composer/ezsystems/ezpublish-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.4.14.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-39j2-4p9j-5w4j/GHSA-39j2-4p9j-5w4j.json"}}],"schema_version":"1.9.0"}