-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ezsystems/repository-forms | composer | >= 2.5.0, < 2.5.15 | 2.5.15 |
The vulnerability stemmed from ineffective subtree limitations in role assignments. The patch added Twig blocks (ez_limitation_memberof_value and ez_limitation_role_value) to handle limitation values, indicating these were missing in vulnerable versions. Without these blocks, the system failed to properly enforce subtree restrictions when rendering/persisting role assignments, allowing Company admins to bypass limitations. The direct correlation between the added blocks and the described vulnerability mechanism supports high confidence.