PT-2018-5247 · Plone Foundation · Plone

Published

2018-01-03

·

Updated

2022-05-14

·

CVE-2017-1000482

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Plone versions 2.5 through 5.1rc1
Description The issue allows a member of the Plone site to set JavaScript in the home page property of their profile. This JavaScript is executed when a visitor clicks the home page link on the author page.
Recommendations For Plone versions 2.5 through 5.1rc1, consider disabling the ability to set JavaScript in the home page property of user profiles until a fix is available. Restrict access to the author page to minimize the risk of exploitation. Avoid using the home page property in user profiles until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000482
GHSA-859J-668V-MRR6
PYSEC-2018-71

Affected Products

Plone