CVE-2022-25336

MEDIUM

Ibexa EZ Platform Kernel < 1.3.12 - IDOR

Title source: rule
STIX 2.1

Description

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path and filename can be correctly deduced.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-639
Status published
Products (2)
ezsystems/ezplatform-kernel 1.3.0 - 1.3.12Packagist
ibexa/ez_platform_kernel 1.3.0 - 1.3.12
Published Feb 18, 2022
Tracked Since Feb 18, 2026