PT-2021-18016 · Plone Cms · Plone Cms

Piyush Patil

·

Published

2021-03-24

·

Updated

2022-05-24

·

CVE-2021-29002

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Plone CMS version 5.2.3
Description: A stored cross-site scripting (XSS) issue exists in the site-controlpanel via the form.widgets.site title parameter. This allows for potential malicious script execution.
Recommendations: For Plone CMS version 5.2.3, consider restricting access to the site-controlpanel until a patch is available. As a temporary workaround, avoid using the form.widgets.site title parameter in the affected site-controlpanel to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29002
GHSA-38G6-X6JV-JWFF
PYSEC-2021-889

Affected Products

Plone Cms