Skip to main content

Vendor/product archive

ibexa / ez_platform_kernel CVEs

Beta · best-effort

7 CVEs tagged to ibexa / ez_platform_kernel2 Critical, 1 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2021-46876

Published Mar 12, 2023

An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46875

Published Mar 12, 2023

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25337

Published Feb 18, 2022

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-25336

Published Feb 18, 2022

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1