Cross Site Scripting Vulnerability in eZPublish Platform by eZ Systems AS
CVE-2020-23065

5.4MEDIUM

Key Information:

Vendor

Ibexa

Vendor
CVE Published:
26 June 2023

What is CVE-2020-23065?

A Cross Site Scripting vulnerability exists in the eZPublish Platform and its legacy version, allowing remote authenticated attackers to potentially execute arbitrary code through the exploitation of the video-js.swf file. This can lead to unauthorized actions on behalf of users and the exposure of sensitive information. It is crucial for users to apply the necessary security measures and updates to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.