Cross-Site Scripting Vulnerability in eZ Platform Ibexa Kernel by eZ Systems
CVE-2021-46875
6.1MEDIUM
What is CVE-2021-46875?
A vulnerability exists in eZ Platform Ibexa Kernel prior to version 1.3.1.1 that enables attackers to upload malicious JavaScript code masquerading as .html or .js files. This could lead to Cross-Site Scripting (XSS) attacks, potentially allowing the execution of arbitrary scripts in the context of the victim's browser. This highlights the importance of proper file handling and content validation to ensure the security of web applications.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
