{"id":"GHSA-39j2-4p9j-5w4j","aliases":[],"url":"https://o3.security/vulnerability/GHSA-39j2-4p9j-5w4j","summary":"Ez Platform Object Injection in legacy shop module","details":"This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity.","published":"2024-05-15T21:32:29Z","modified":"2024-11-29T05:26:35.611726Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ezsystems/ezpublish-legacy","fixedVersion":"2019.3.5.1"},{"ecosystem":"Packagist","name":"ezsystems/ezpublish-legacy","fixedVersion":"2017.12.7.3"},{"ecosystem":"Packagist","name":"ezsystems/ezpublish-legacy","fixedVersion":"5.4.14.2"}],"fix":null,"references":[{"type":"WEB","url":"https://ezplatform.com/security-advisories/ibexa-sa-2020-006-object-injection-in-legacy-shop-module"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/ezpublish-legacy/2020-10-05-1.yaml"},{"type":"PACKAGE","url":"https://github.com/ezsystems/ezpublish-legacy"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:26:35.611726Z"}}