CVE-2021-46875Cross-site Scripting in EZ Platform Kernel

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 32.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
Latest updateMar 19
PublishedMar 12

Description

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDibexa/ez_platform_kernel1.2.01.2.5.1+3
Packagistezsystems/ezplatform-kernel1.3.01.3.1.1+1
Packagistezsystems/ezpublish-kernel7.0.07.5.15.2+1

Patches

🔴Vulnerability Details

2
OSV
Cross-site scripting in eZ Platform Kernel2021-03-19
GHSA
Cross-site scripting in eZ Platform Kernel2021-03-19