PT-2010-4006 · Zope · Plone
Published
2010-06-23
·
Updated
2022-05-17
·
CVE-2010-2422
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Plone versions 2.1 through 3.3.4
Plone versions 2.1 through 3.3.5 before hotfix 20100612
Description
The issue is related to a cross-site scripting (XSS) vulnerability in PortalTransforms. This allows remote attackers to inject arbitrary web script or HTML via the
safe html transform.Recommendations
For Plone versions 2.1 through 3.3.4, apply hotfix 20100612 to resolve the issue.
For Plone versions 2.1 through 3.3.5 before hotfix 20100612, apply hotfix 20100612 to resolve the issue.
As a temporary workaround, consider restricting access to the
safe html transform until a patch is available.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plone