CVE-2012-5502: XSS
Cross-site scripting (XSS) vulnerability in safehtml.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5502?
The CVE-2012-5502 vulnerability is classified as a cross-site scripting (XSS) vulnerability, which can pose a significant risk to users.
How do I fix CVE-2012-5502?
To remediate CVE-2012-5502, upgrade to Plone version 4.2.3 or higher.
Which versions of Plone are affected by CVE-2012-5502?
CVE-2012-5502 affects Plone versions prior to 4.2.3 and some versions of 4.3 before beta 1.
What type of attack does CVE-2012-5502 enable?
CVE-2012-5502 enables remote authenticated users to inject arbitrary web script or HTML, leading to potential XSS attacks.
Who is at risk from CVE-2012-5502?
Remote authenticated users with permissions to edit content are at risk from CVE-2012-5502 due to the ability to inject malicious scripts.