Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch prior to 4.6.10, the validator for the RichText fieldtype blocklists `javascript:` and `vbscript:` in links to prevent XSS. This can leave other options open, and the check can be circumvented using upper case. Content editing permissions for RichText content is required to exploit this vulnerability, which typically means Editor role or higher. The fix implements an allowlist instead, which allows only approved link protocols. The new check is case insensitive. Version 4.6.10 contains a patch for this issue. No known workarounds are available.
History

Fri, 16 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibexa
Ibexa ezplatform-richtext
Ibexa fieldtype-richtext
CPEs cpe:2.3:a:ibexa:ezplatform-richtext:*:*:*:*:*:*:*:*
cpe:2.3:a:ibexa:fieldtype-richtext:*:*:*:*:*:*:*:*
Vendors & Products Ibexa
Ibexa ezplatform-richtext
Ibexa fieldtype-richtext
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Aug 2024 23:30:00 +0000

Type Values Removed Values Added
Description Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch prior to 4.6.10, the validator for the RichText fieldtype blocklists `javascript:` and `vbscript:` in links to prevent XSS. This can leave other options open, and the check can be circumvented using upper case. Content editing permissions for RichText content is required to exploit this vulnerability, which typically means Editor role or higher. The fix implements an allowlist instead, which allows only approved link protocols. The new check is case insensitive. Version 4.6.10 contains a patch for this issue. No known workarounds are available.
Title Persistent Cross-site Scripting in Ibexa RichText Field Type
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-15T23:17:19.044Z

Updated: 2024-08-16T14:05:43.757Z

Reserved: 2024-08-09T14:23:55.513Z

Link: CVE-2024-43369

cve-icon Vulnrichment

Updated: 2024-08-16T14:05:29.069Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-16T02:15:16.600

Modified: 2024-08-19T13:00:23.117

Link: CVE-2024-43369

cve-icon Redhat

No data.