PT-2010-4006 · Zope · Plone
Publicado
2010-06-23
·
Atualizado
2022-05-17
·
CVE-2010-2422
CVSS v4.0
5.3
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Plone versions 2.1 through 3.3.4
Plone versions 2.1 through 3.3.5 before hotfix 20100612
Description
The issue is related to a cross-site scripting (XSS) vulnerability in PortalTransforms. This allows remote attackers to inject arbitrary web script or HTML via the
safe html transform.Recommendations
For Plone versions 2.1 through 3.3.4, apply hotfix 20100612 to resolve the issue.
For Plone versions 2.1 through 3.3.5 before hotfix 20100612, apply hotfix 20100612 to resolve the issue.
As a temporary workaround, consider restricting access to the
safe html transform until a patch is available.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Plone