CVE Explorer
CVE-2025-67719
Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the validation of the previous password not to run as expected. This makes it possible for a logged in user to change their password in the back office without knowing the previous password. For example, if a user logs into their account and walks away without locking t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"user","vendor":"ibexa","versions":[{"status":"affected","version":">= 5.0.0-beta1, < 5.0.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5ebf0422e05244176f8f989c431d27940d947e90308d58c977223caadcdf464f · sha256:a3b91c303f4da72b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":8.5,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5ebf0422e05244176f8f989c431d27940d947e90308d58c977223caadcdf464f · sha256:a3b91c303f4da72b… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-620","description":"CWE-620: Unverified Password Change","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5ebf0422e05244176f8f989c431d27940d947e90308d58c977223caadcdf464f · sha256:a3b91c303f4da72b… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://developers.ibexa.co/security-advisories/ibexa-sa-2025-005-password-change-and-xss-vulnerabilities-in-back-office","tags":["x_refsource_MISC"],"url":"https://developers.ibexa.co/security-advisories/ibexa-sa-2025-005-password-change-and-xss-vulnerabilities-in-back-office"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5ebf0422e05244176f8f989c431d27940d947e90308d58c977223caadcdf464f · sha256:a3b91c303f4da72b… · /containers/cna/references/2
{"name":"https://github.com/ibexa/user/commit/9d485bf385e6401c9f7ee80287d8ccd00f73dcf4","tags":["x_refsource_MISC"],"url":"https://github.com/ibexa/user/commit/9d485bf385e6401c9f7ee80287d8ccd00f73dcf4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5ebf0422e05244176f8f989c431d27940d947e90308d58c977223caadcdf464f · sha256:a3b91c303f4da72b… · /containers/cna/references/1
{"name":"https://github.com/ibexa/user/security/advisories/GHSA-x93p-w2ch-fg67","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ibexa/user/security/advisories/GHSA-x93p-w2ch-fg67"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5ebf0422e05244176f8f989c431d27940d947e90308d58c977223caadcdf464f · sha256:a3b91c303f4da72b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.