peter bassill · operator
$ cve CVE-2014-2552 JSON

CVE-2014-2552

9.8
CRITICAL · CVSS 3.0 · EPSS 3.5% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.51% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploitnone known
Published2018-04-27
Last modified2026-06-17

Affected (1)

VendorProduct
brookinsconsultingcollected information export

References

→ the Explorer  ·  watch your stack  ·  NVD