Password Change Vulnerability in Ibexa DXP
CVE-2025-67719
What is CVE-2025-67719?
Ibexa DXP, a robust digital experience platform, suffers from a significant vulnerability due to a flaw in its password validation process. In versions 5.0.0-beta1 to 5.0.3, an error was introduced during the transition from version 4 to version 5, allowing logged-in users to change their passwords without knowing the previous one. This could lead to unauthorized access if a user leaves their session unattended. With an attacker able to exploit an open session, the legitimate user could find themselves locked out of their account. The issue has been addressed in version 5.0.4, enhancing the security of user password changes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
user >= 5.0.0-beta1, < 5.0.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
