Vigilance.fr - Ibexa DXP: external XML entity injection via RichText Field Type, analyzed on 09/04/2025
June 2025 by Vigilance.fr
An attacker can transmit malicious XML data to Ibexa DXP, via RichText Field Type, in order to read a file, scan sites, or trigger a denial of service.
Plus d'information sur : https://vigilance.fr/vulnerability/Ibexa-DXP-external-XML-entity-injection-via-RichText-Field-Type-46842