PT-2018-5247 · Plone Foundation · Plone
Published
2018-01-03
·
Updated
2022-05-14
·
CVE-2017-1000482
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Plone versions 2.5 through 5.1rc1
Description
The issue allows a member of the Plone site to set JavaScript in the
home page property of their profile. This JavaScript is executed when a visitor clicks the home page link on the author page.Recommendations
For Plone versions 2.5 through 5.1rc1, consider disabling the ability to set JavaScript in the
home page property of user profiles until a fix is available. Restrict access to the author page to minimize the risk of exploitation. Avoid using the home page property in user profiles until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plone