Miggo Logo

GHSA-w9p3-26fx-5mp3: eZ Platform Admin UI is vulnerable to Cross-site Scripting (XSS)

N/A

CVSS Score

Basic Information

CVE ID
-
EPSS Score
-
Published
5/15/2024
Updated
5/15/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
-
Package NameEcosystemVulnerable VersionsFirst Patched Version
ezsystems/platform-ui-assets-bundlecomposer>= 4.2.0, < 4.2.34.2.3

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability originates from outdated third-party dependencies (CKEditor <4.14 and AlloyEditor <2.11.9) used by the eZ Platform Admin UI, rather than specific functions within the eZ Platform codebase itself. The XSS vulnerability exists in CKEditor's handling of 'protected' comments, which is a feature implemented within CKEditor's core parsing and rendering logic. Since the advisory doesn't provide specific code references or patches within the eZ Platform components, and the fix involves updating dependencies rather than modifying eZ Platform's own functions, we cannot identify vulnerable functions in the eZ Platform code with high confidence. The primary vulnerable components are in the third-party libraries' comment processing mechanisms.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

T**r* is *n XSS vuln*r**ility in *K**itor, w*i** is us** *y *lloy**itor, w*i** is us** in *Z Pl*t*orm **min UI. S*ripts **n ** inj**t** t*rou** sp**i*lly *r**t** "prot**t**" *omm*nts. W* *r* not sur* it is *xploit**l* in *Z Pl*t*orm, *ut r**omm*n* in

Reasoning

T** vuln*r**ility ori*in*t*s *rom out**t** t*ir*-p*rty **p*n**n*i*s (*K**itor <*.** *n* *lloy**itor <*.**.*) us** *y t** *Z Pl*t*orm **min UI, r*t**r t**n sp**i*i* *un*tions wit*in t** *Z Pl*t*orm *o****s* its*l*. T** XSS vuln*r**ility *xists in `*K*