Wiz Agents & Workflows are here
Vulnerability DatabaseGHSA-2w9p-xxqr-h253

GHSA-2w9p-xxqr-h253
PHP vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-2w9p-xxqr-h253) is an object injection vulnerability discovered in the SiteAccessMatchListener component of eZ Platform. The issue was disclosed on May 20, 2020, affecting ezsystems/ezplatform-kernel versions 1.0.0 to 1.0.2.1. This high-severity vulnerability impacts all sites running the affected versions of eZ Platform (EZ Platform).

Technical details

The vulnerability exists in the SiteAccessMatchListener component and could potentially lead to remote code execution (RCE). The initial fix introduced some bugs, particularly affecting compound siteaccess matchers, which required subsequent patches. The issue was resolved in ezsystems/ezplatform-kernel v1.0.3, and corresponding fixes were also released for ezpublish-kernel in versions v7.5.8, v6.13.6.4, and v5.4.15 (GitHub Advisory).

Impact

The vulnerability is classified as high severity and could lead to remote code execution (RCE), which represents a very serious threat to affected systems. The impact potentially affects all sites running the vulnerable versions of the software (EZ Platform).

Mitigation and workarounds

The vulnerability has been patched in ezsystems/ezplatform-kernel version 1.0.3. Users should upgrade to the following fixed versions: ezsystems/ezplatform-kernel v1.0.3, ezsystems/ezpublish-kernel v7.5.8, v6.13.6.4, or v5.4.15. The security update is distributed via Composer (GitHub Advisory).

Community reactions

The vulnerability was responsibly disclosed by Serhey Dolgushev from Contextual Code, demonstrating effective collaboration between security researchers and the software maintainers (EZ Platform).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34728HIGH8.7
  • PHPPHP
  • phpmyfaq/phpmyfaq
NoYesApr 02, 2026
CVE-2026-34598HIGH7.1
  • PHPPHP
  • yeswiki/yeswiki
NoYesApr 02, 2026
CVE-2026-34973MEDIUM6.9
  • PHPPHP
  • thorsten/phpmyfaq
NoYesApr 02, 2026
CVE-2026-34729MEDIUM6.1
  • PHPPHP
  • phpmyfaq/phpmyfaq
NoYesApr 02, 2026
CVE-2026-34974MEDIUM5.4
  • PHPPHP
  • thorsten/phpmyfaq
NoYesApr 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management