Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Igor Margitich

#47389of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2021-20171
5.4
2021-05-21
Plone · Plone · CVE-2021-33513
**Name of the Vulnerable Software and Affected Versions** Plone versions through 5.2.4 **Description** The issue allows for cross-site scripting (XSS) attacks via the `inline diff` methods in `Products.CMFDiffTool`. This can potentially lead to malicious script execution on the client-side. **Recommendations** For Plone versions through 5.2.4, consider disabling the `inline diff` methods in `Products.CMFDiffTool` as a temporary workaround until a patch is available. Restrict access to the affected `Products.CMFDiffTool` module to minimize the risk of exploitation.