An issue was discovered in eZ Platform Ibexa Kernel before 1.3.1.1. An XSS attack can occur because JavaScript code can be uploaded in a .html or .js file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ezsystems/ezpublish-kernel(Packagist) | 6.13.0 | 6.13.8.2 | N/A |
| ezsystems/ezpublish-kernel(Packagist) | 7.5.0 | 7.5.15.2 | N/A |
| ezsystems/ezplatform-kernel(Packagist) | 1.2.0 | 1.2.5.1 | N/A |
| ezsystems/ezplatform-kernel(Packagist) | 1.3.0 | 1.3.1.1 | N/A |
CVSS Metrics