PT-2023-12596 · Ibexa · Ez Platform Ibexa Kernel
Published
2021-03-19
·
Updated
2025-03-04
·
CVE-2021-46875
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
eZ Platform Ibexa Kernel versions prior to 1.3.1.1
Description
An issue allows JavaScript code to be uploaded in .html or .js files, leading to a potential XSS attack when links to these files are accessed. This can occur due to the ability to upload certain file types. The estimated number of potentially affected devices is not specified.
Recommendations
For versions prior to 1.3.1.1, add common types of scriptable file types to the configuration of the existing filetype blacklist feature by modifying the
ezsettings.default.io.file storage.file type blacklist setting. It is essential to adapt this setting according to specific needs and not add file types to the blacklist that are required for upload. Consider using an approval workflow for certain content types, such as SVG files, if they need to be uploaded.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ez Platform Ibexa Kernel