CVE-2010-2422: XSS
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safehtml transform.
Other sources
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.5 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safehtml transform.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2422?
CVE-2010-2422 has been classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2010-2422?
To remediate CVE-2010-2422, update to Plone version 3.3.6 or later.
What applications are affected by CVE-2010-2422?
CVE-2010-2422 affects Plone versions from 2.1 to 3.3.5.
What type of vulnerability is CVE-2010-2422?
CVE-2010-2422 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
Can CVE-2010-2422 be exploited remotely?
Yes, CVE-2010-2422 can be exploited by remote attackers to execute scripts in a victim’s browser.