CVE-2011-1340: XSS
Cross-site scripting (XSS) vulnerability in skins/plonetemplates/defaulterrormessage.pt in Plone before 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the typename parameter to Members/ipa/createObject.
Other sources
Cross-site scripting (XSS) vulnerability in skins/plonetemplates/defaulterrormessage.pt in Plone before 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the typename parameter to Members/ipa/createObject.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1340?
CVE-2011-1340 is classified as a cross-site scripting (XSS) vulnerability with medium severity.
How do I fix CVE-2011-1340?
To fix CVE-2011-1340, upgrade Plone to version 2.5.3 or later.
What versions of Plone are affected by CVE-2011-1340?
CVE-2011-1340 affects Plone versions prior to 2.5.3, including versions 1.0 through 2.5.2.
Can CVE-2011-1340 lead to unauthorized access?
Yes, CVE-2011-1340 can allow attackers to execute arbitrary web scripts, potentially leading to unauthorized actions.
How can I determine if my Plone installation is vulnerable to CVE-2011-1340?
Check the version of your Plone installation; if it is below 2.5.3, it is vulnerable to CVE-2011-1340.