Vulnerability Description
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibexa | Ez Platform Kernel | >= 1.3.0, < 1.3.12 |
Related Weaknesses (CWE)
References
- https://developers.ibexa.co/security-advisories/ibexa-sa-2022-001-image-filenameMitigationVendor Advisory
- https://developers.ibexa.co/security-advisories/ibexa-sa-2022-001-image-filenameMitigationVendor Advisory
FAQ
What is CVE-2022-25336?
CVE-2022-25336 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be c...
How severe is CVE-2022-25336?
CVE-2022-25336 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25336?
Check the references section above for vendor advisories and patch information. Affected products include: Ibexa Ez Platform Kernel.