CVE-2016-7136: XSS
Published Mar 7, 2017
·Updated
z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.
Affected Software
51 affected components
pip/plone>=4.0.0<=4.3.11
pip/plone>=5.0.0<=5.0.6
Plone plone=4.0
Plone plone=4.0.1
Plone plone=4.0.2
Plone plone=4.0.3
Plone plone=4.0.4
Plone plone=4.0.5
Plone plone=4.0.7
Plone plone=4.0.8
Plone plone=4.0.9
Plone plone=4.0.10
Plone plone=4.1
Plone plone=4.1.1
Plone plone=4.1.2
Plone plone=4.1.3
Plone plone=4.1.4
Plone plone=4.1.5
Plone plone=4.1.6
Plone plone=4.2
Plone plone=4.2.1
Plone plone=4.2.2
Plone plone=4.2.3
Plone plone=4.2.4
Plone plone=4.2.5
Plone plone=4.2.6
Plone plone=4.2.7
Plone plone=4.3
Plone plone=4.3.1
Plone plone=4.3.2
Plone plone=4.3.3
Plone plone=4.3.4
Plone plone=4.3.5
Plone plone=4.3.6
Plone plone=4.3.7
Plone plone=4.3.8
Plone plone=4.3.9
Plone plone=4.3.10
Plone plone=4.3.11
Plone plone=5.0
Plone plone=5.0-a1
Plone plone=5.0-rc1
Plone plone=5.0-rc2
Plone plone=5.0-rc3
Plone plone=5.0.1
Plone plone=5.0.2
Plone plone=5.0.3
Plone plone=5.0.4
Plone plone=5.0.5
Plone plone=5.0.6
Plone plone=5.1a1
Remediation
Patch Available
Patch Available
Event History
Mar 7, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 14, 2022
Advisory Published
02:46 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-7136?
CVE-2016-7136 is classified as a moderate severity vulnerability that allows remote attackers to perform cross-site scripting (XSS) attacks.
2
How do I fix CVE-2016-7136?
To fix CVE-2016-7136, upgrade your Plone CMS to version 5.0.7 or later or apply any security patches provided by the Plone team.
3
What versions are affected by CVE-2016-7136?
CVE-2016-7136 affects Plone CMS versions 5.0.6 and earlier, as well as versions 4.3.11 and earlier.
4
What type of attack is possible with CVE-2016-7136?
CVE-2016-7136 allows for cross-site scripting (XSS) attacks via crafted GET requests.
5
Is my Plone installation vulnerable if it's not updated?
Yes, if your Plone installation is not updated to a version that addresses CVE-2016-7136, it remains vulnerable to exploitation.