Plone Cms · Plone Cms · CVE-2021-29002
Name of the Vulnerable Software and Affected Versions:
Plone CMS version 5.2.3
Description:
A stored cross-site scripting (XSS) issue exists in the site-controlpanel via the `form.widgets.site title` parameter. This allows for potential malicious script execution.
Recommendations:
For Plone CMS version 5.2.3, consider restricting access to the site-controlpanel until a patch is available. As a temporary workaround, avoid using the `form.widgets.site title` parameter in the affected site-controlpanel to minimize the risk of exploitation.