CVE-2022-48365

HIGH

Ibexa Digital Experience Platform 3.3.0-3.3.27 - Improper Privilege Management via Company Admin Role

Title source: llm
STIX 2.1

Description

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.

Scores

CVSS v3 7.2
EPSS 0.0086
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (5)
ezsystems/ezplatform-kernel 1.3.0 - 1.3.26Packagist
ezsystems/ezpublish-kernel 7.5.0 - 7.5.30Packagist
ibexa/digital_experience_platform 3.3.0 - 3.3.28
ibexa/ez_platform 2.5.0 - 2.5.31
ibexa/ez_platform_kernel 1.3.0 - 1.3.26
Published Mar 12, 2023
Tracked Since Feb 18, 2026