Vulnerability Description
Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Brookinsconsulting | Collected Information Export | 1.1.0 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92129Third Party AdvisoryVDB Entry
- https://github.com/brookinsconsulting/bccie/commit/d11811baccf265ff567dddca03cacPatchThird Party Advisory
- https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2014-004/Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92129Third Party AdvisoryVDB Entry
- https://github.com/brookinsconsulting/bccie/commit/d11811baccf265ff567dddca03cacPatchThird Party Advisory
- https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2014-004/Third Party Advisory
FAQ
What is CVE-2014-2552?
CVE-2014-2552 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.
How severe is CVE-2014-2552?
CVE-2014-2552 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2014-2552?
Check the references section above for vendor advisories and patch information. Affected products include: Brookinsconsulting Collected Information Export.