Cross-Site Scripting Vulnerability in eZ Platform Ibexa Kernel by eZ Systems
CVE-2021-46875

6.1MEDIUM

Key Information:

Vendor

Ibexa

Vendor
CVE Published:
12 March 2023

What is CVE-2021-46875?

A vulnerability exists in eZ Platform Ibexa Kernel prior to version 1.3.1.1 that enables attackers to upload malicious JavaScript code masquerading as .html or .js files. This could lead to Cross-Site Scripting (XSS) attacks, potentially allowing the execution of arbitrary scripts in the context of the victim's browser. This highlights the importance of proper file handling and content validation to ensure the security of web applications.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.