CVE Feed

    Dashboard / CVE / CVE-2024-43369

    CVE-2024-43369

    Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch prior to 4.6.10, the validator for the RichText fieldtype blocklists `javascript:` and `vbscript:` in links to prevent XSS. This can leave other options open, and the check can be circumvented using upper case. Content editing permissions for RichText content is required to exploit this vulnerability, which typically means Editor role or higher. The fix implements an allowlist instead, which allows only approved link protocols. The new check is case insensitive. Version 4.6.10 contains a patch for this issue. No known workarounds are available.

    Published:Aug 15, 2024
    Last Modified:Apr 15, 2026
    EPS:Aug 15, 2024
    EPSS Score:0.00177
    CVSS Score:7.2

    Affected Products

    Vendor
    Ibexa
    Product
    Ezplatform-richtext
    Vendor
    Ibexa
    Product
    Fieldtype-richtext

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High