Vulnerability DatabaseGHSA-9jp8-cwwx-p64q

GHSA-9jp8-cwwx-p64q
PHP vulnerability analysis and mitigation

Overview

A cross-site scripting (XSS) vulnerability was discovered in ezsystems/ezplatform-richtext and ezsystems/ezplatform-admin-ui, identified as GHSA-9jp8-cwwx-p64q. The vulnerability was published on November 25, 2021, affecting versions v2.3. of ezplatform-richtext and v1.5. of ezplatform-admin-ui. The issue was specifically related to the rich text editor's handling of custom tag attributes (GitHub Advisory, Ibexa Advisory).

Technical details

The vulnerability stems from the rich text editor's failure to properly escape attribute data when previewing custom tags. This security flaw affects Ibexa DXP v3.3 and eZ Platform v2.5. The issue was addressed in the patched versions ezsystems/ezplatform-richtext v2.3.7.1 and ezsystems/ezplatform-admin-ui v1.5.25.1 (Ibexa Advisory).

Impact

While the frontend content view remains unaffected, the vulnerability could be exploited by editors to launch attacks against other editors who have access to rich text content editing capabilities. The security issue is specifically contained within the editor preview functionality (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed by ensuring custom tag attribute data is properly escaped in the editor. Users are advised to upgrade to the patched versions: ezsystems/ezplatform-richtext v2.3.7.1 or ezsystems/ezplatform-admin-ui v1.5.25.1 (Ibexa Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-898v-775g-777cCRITICAL9.4
  • PHPPHP
  • neuron-core/neuron-ai
NoYesDec 09, 2025
GHSA-5j8p-438x-rgg5CRITICAL9.3
  • PHPPHP
  • onelogin/php-saml
NoYesDec 09, 2025
GHSA-j8g6-5gqc-mq36HIGH8.2
  • PHPPHP
  • neuron-core/neuron-ai
NoYesDec 09, 2025
GHSA-pvcv-q3q7-266gHIGH8.1
  • PHPPHP
  • filament/filament
NoYesDec 09, 2025
GHSA-6w82-v552-wjw2HIGH7.1
  • PHPPHP
  • shopware/shopware
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management