An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-03-12 05:15
Updated : 2025-03-04 22:15
NVD link : CVE-2021-46875
Mitre link : CVE-2021-46875
CVE.ORG link : CVE-2021-46875
JSON object : View
Products Affected
ibexa
- ez_platform_kernel
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')