PT-2024-40225 · Ibexa · Ibexa/Core

Published

2024-03-20

·

Updated

2024-03-20

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: ibexa core (affected versions not specified)
Description: The issue allows unwanted file types to be stored even if they are not easily accessible due to the content not being published. This occurs when file validation is configured to reject certain files by file type, but the file can still be saved when saving the content draft. An attacker would need existing access to create content with a file field type to exploit this.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-9J39-4686-M3C4

Affected Products

Ibexa/Core