Ibexa Admin UI Bundle is all the necessary parts to run the Ibexa DXP Back Office interface. The Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. This issue has been patched in version 4.6.14. All users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Mon, 02 Dec 2024 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 19:00:00 +0000

Type Values Removed Values Added
Description Ibexa Admin UI Bundle is all the necessary parts to run the Ibexa DXP Back Office interface. The Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any existing injected XSS will not run. This issue has been patched in version 4.6.14. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Cross-site Scripting in a field that is used in the Content name pattern in ibexa/admin-ui
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-12-02T11:09:34.840Z

Reserved: 2024-11-22T17:30:02.145Z

Link: CVE-2024-53864

cve-icon Vulnrichment

Updated: 2024-12-02T11:08:15.051Z

cve-icon NVD

Status : Deferred

Published: 2024-11-29T19:15:09.577

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-53864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.