CVE-2008-4571: XSS
Cross-site scripting (XSS) vulnerability in the LiveSearch module in Plone before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the Description field for search results, as demonstrated using the onerror Javascript even in an IMG tag.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4571?
CVE-2008-4571 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2008-4571?
To resolve CVE-2008-4571, upgrade to Plone version 3.0.4 or later.
Which versions of Plone are affected by CVE-2008-4571?
CVE-2008-4571 affects Plone versions up to and including 3.0.3, as well as several 2.5 versions.
What type of vulnerability is CVE-2008-4571?
CVE-2008-4571 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject scripts into web pages.
What is the exploit method for CVE-2008-4571?
Attackers can exploit CVE-2008-4571 by using the Description field for search results to inject arbitrary web scripts or HTML.