PT-2023-12596 · Ibexa · Ez Platform Ibexa Kernel
Publicado
2021-03-19
·
Atualizado
2025-03-04
·
CVE-2021-46875
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
eZ Platform Ibexa Kernel versions prior to 1.3.1.1
Description
An issue allows JavaScript code to be uploaded in .html or .js files, leading to a potential XSS attack when links to these files are accessed. This can occur due to the ability to upload certain file types. The estimated number of potentially affected devices is not specified.
Recommendations
For versions prior to 1.3.1.1, add common types of scriptable file types to the configuration of the existing filetype blacklist feature by modifying the
ezsettings.default.io.file storage.file type blacklist setting. It is essential to adapt this setting according to specific needs and not add file types to the blacklist that are required for upload. Consider using an approval workflow for certain content types, such as SVG files, if they need to be uploaded.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ez Platform Ibexa Kernel