Unverified Password Change in Ibexa DXP - #VU119819

 

Unverified Password Change in Ibexa DXP - #VU119819

Published: December 10, 2025


Vulnerability identifier: #VU119819
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-620
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform unverified password change.

The vulnerability exists due to an error in the validation code which caused the validation of the previous password to fail. An attacker with access to the user's current session can change passwords in the back office without knowing the previous password.


Affected software

Ibexa DXP

Remediation

Install updates from vendor's website.

Ibexa DXP - addressed in versions 4.6.26, 5.0.4

External References

Related Security Bulletins