Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch prior to 4.6.10, the validator for the RichText fieldtype blocklists `javascript:` and `vbscript:` in links to prevent XSS. This can leave other options open, and the check can be circumvented using upper case. Content editing permissions for RichText content is required to exploit this vulnerability, which typically means Editor role or higher. The fix implements an allowlist instead, which allows only approved link protocols. The new check is case insensitive. Version 4.6.10 contains a patch for this issue. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ibexa
Ibexa ezplatform-richtext Ibexa fieldtype-richtext |
|
CPEs | cpe:2.3:a:ibexa:ezplatform-richtext:*:*:*:*:*:*:*:* cpe:2.3:a:ibexa:fieldtype-richtext:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibexa
Ibexa ezplatform-richtext Ibexa fieldtype-richtext |
|
Metrics |
ssvc
|
Thu, 15 Aug 2024 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch prior to 4.6.10, the validator for the RichText fieldtype blocklists `javascript:` and `vbscript:` in links to prevent XSS. This can leave other options open, and the check can be circumvented using upper case. Content editing permissions for RichText content is required to exploit this vulnerability, which typically means Editor role or higher. The fix implements an allowlist instead, which allows only approved link protocols. The new check is case insensitive. Version 4.6.10 contains a patch for this issue. No known workarounds are available. | |
Title | Persistent Cross-site Scripting in Ibexa RichText Field Type | |
Weaknesses | CWE-79 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-15T23:17:19.044Z
Updated: 2024-08-16T14:05:43.757Z
Reserved: 2024-08-09T14:23:55.513Z
Link: CVE-2024-43369
Vulnrichment
Updated: 2024-08-16T14:05:29.069Z
NVD
Status : Awaiting Analysis
Published: 2024-08-16T02:15:16.600
Modified: 2024-08-19T13:00:23.117
Link: CVE-2024-43369
Redhat
No data.