PT-2023-12596 · Ibexa · Ez Platform Ibexa Kernel

Publicado

2021-03-19

·

Atualizado

2025-03-04

·

CVE-2021-46875

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions eZ Platform Ibexa Kernel versions prior to 1.3.1.1
Description An issue allows JavaScript code to be uploaded in .html or .js files, leading to a potential XSS attack when links to these files are accessed. This can occur due to the ability to upload certain file types. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 1.3.1.1, add common types of scriptable file types to the configuration of the existing filetype blacklist feature by modifying the ezsettings.default.io.file storage.file type blacklist setting. It is essential to adapt this setting according to specific needs and not add file types to the blacklist that are required for upload. Consider using an approval workflow for certain content types, such as SVG files, if they need to be uploaded.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-46875
GHSA-C737-JHWR-FQXJ
GHSA-MRVJ-7Q4F-5P42

Produtos afetados

Ez Platform Ibexa Kernel