PT-2022-17220 · Ibexa · Ibexa Dxp

Christoph Rottermanner

+1

·

Published

2022-02-18

·

Updated

2022-03-03

·

CVE-2022-25337

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ibexa DXP ezsystems/ezpublish-kernel versions 7.5.x through 7.5.25 Ibexa DXP ezsystems/ezpublish-kernel versions 1.3.x through 1.3.11
Description The issue allows injection attacks via image filenames when image files are uploaded. This is possible because not all possible attack vectors are removed from the original file name. Additionally, direct access to the images is not access controlled, which can allow images not meant to be publicly accessible to be accessed if the image path and filename are correctly deduced or guessed.
Recommendations For versions 7.5.x through 7.5.25, update to version 7.5.26 or later to resolve the issue. For versions 1.3.x through 1.3.11, update to version 1.3.12 or later to resolve the issue. As a temporary workaround, consider restricting access to image uploading functionality to minimize the risk of exploitation.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25337
GHSA-XWV6-V7QX-F5JC

Affected Products

Ibexa Dxp