An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-03-11 21:15
Updated : 2023-03-16 11:21
NVD link : CVE-2021-46875
Mitre link : CVE-2021-46875
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
ibexa
- ez_platform_kernel