Intel

AIKIDO-2025-10958

ibexa/user is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 15, 2025

45

Medium Risk

This Affects:

PHPibexa/user
4.6.0 - 4.6.25
Fixed in 4.6.26
5.0.0 - 5.0.3
Fixed in 5.0.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to insufficient input filtering in the back-office share dialog, allowing users to inject JavaScript code. There is no indication that the injected content is stored or subsequently rendered to other users, which limits the scope and impact of the vulnerability to the user performing the action.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

ibexa/user is vulnerable to Cross-site Scripting (XSS) in versions 4.6.0 - 4.6.25 and 5.0.0 - 5.0.3.

How to fix this

Upgrade the ibexa/user library to the patch version.