ezsystems/ezpublish-legacy Security Advisories for v2017.12.4.2 (4)
- 
                        [CRITICAL] eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous TypePKSA-x1cq-96j3-vfs9 CVE-2020-10806 GHSA-54p5-gxq6-j98g Affected version: >=2019,<2019.03.4.2|>=2017,<2017.12.7.2|<5.4.14.1 Reported by: 
 GitHub
- 
                        [HIGH] IBEXA-SA-2020-006 Object Injection in legacy shop modulePKSA-21zv-zmv6-8djw GHSA-82rv-45pc-v28w Affected version: >=2019.3.0,<2019.3.5.1|>=2017.12.0,<2017.12.7.3|>=5.4.0,<5.4.14.2 Reported by: 
 FriendsOfPHP/security-advisories, GitHub
- 
                        [HIGH] EZSA-2020-001 Remote code execution in file uploadsPKSA-8zqw-67xm-djp1 GHSA-p9mp-vq4v-v5m5 Affected version: >=2019.3.0,<2019.3.4.2|>=2017.12.0,<2017.12.7.2|>=5.4.0,<5.4.14.1 Reported by: 
 FriendsOfPHP/security-advisories, GitHub
- 
                        [HIGH] EZSA-2018-009 Do not interpret PHP/PHAR uploadsPKSA-pyck-srww-rjvt GHSA-9895-26wr-4fgv Affected version: >=2018.9.0,<2018.9.1.3|>=2018.6.0,<2018.6.1.4|>=2011.0.0,<2017.12.4.3|>=5.4.0,<5.4.12.3|>=5.3.0,<5.3.12.6 Reported by: 
 FriendsOfPHP/security-advisories, GitHub