PT-2014-2331 · Plone Foundation · Plone

Alan Hoey

·

Published

2014-09-30

·

Updated

2022-05-17

·

CVE-2012-5504

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Plone versions prior to 4.2.3 Plone versions 4.3 prior to beta 1
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML.
Recommendations For versions prior to 4.2.3, update to version 4.2.3 or later. For versions 4.3 prior to beta 1, update to beta 1 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5504
GHSA-5WHW-5CMM-9JW4
PYSEC-2014-46

Affected Products

Plone