Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Matt Moreschi

#47130of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2021-21080
5.4
2021-06-30
Plone · Plone · CVE-2021-35959
Name of the Vulnerable Software and Affected Versions: Plone versions 5.0 through 5.2.4 Description: The issue affects Editors in the folder contents view, where a Contributor can create a folder with a SCRIPT tag in the `description` field, leading to XSS. Recommendations: For Plone versions 5.0 through 5.2.4, consider disabling the folder contents view for Contributors until a patch is available. Restrict access to the description field to minimize the risk of exploitation.