PT-2025-50566 · Ibexa · Ibexa

Published

2025-12-11

·

Updated

2025-12-12

·

CVE-2025-67719

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ibexa versions 5.0.0-beta1 through 5.0.3
Description Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 lack proper password validation during password changes. An error introduced during the transition from version 4 to version 5 prevents the previous password validation from running as expected. This allows a logged-in user to change their password without knowing the previous password. An attacker could exploit this by accessing an unattended session and changing the password, effectively locking the legitimate user out of their account.
Recommendations Upgrade to version 5.0.4.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-67719
GHSA-X93P-W2CH-FG67

Affected Products

Ibexa