First published: Tue Mar 07 2017(Updated: )
Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plone Plone | =3.3 | |
Plone Plone | =3.3.1 | |
Plone Plone | =3.3.2 | |
Plone Plone | =3.3.3 | |
Plone Plone | =3.3.4 | |
Plone Plone | =3.3.5 | |
Plone Plone | =3.3.6 | |
Plone Plone | =4.0 | |
Plone Plone | =4.0.1 | |
Plone Plone | =4.0.2 | |
Plone Plone | =4.0.3 | |
Plone Plone | =4.0.4 | |
Plone Plone | =4.0.5 | |
Plone Plone | =4.0.7 | |
Plone Plone | =4.0.8 | |
Plone Plone | =4.0.9 | |
Plone Plone | =4.0.10 | |
Plone Plone | =4.1 | |
Plone Plone | =4.1.1 | |
Plone Plone | =4.1.2 | |
Plone Plone | =4.1.3 | |
Plone Plone | =4.1.4 | |
Plone Plone | =4.1.5 | |
Plone Plone | =4.1.6 | |
Plone Plone | =4.2 | |
Plone Plone | =4.2.1 | |
Plone Plone | =4.2.2 | |
Plone Plone | =4.2.3 | |
Plone Plone | =4.2.4 | |
Plone Plone | =4.2.5 | |
Plone Plone | =4.2.6 | |
Plone Plone | =4.2.7 | |
Plone Plone | =4.3 | |
Plone Plone | =4.3.1 | |
Plone Plone | =4.3.2 | |
Plone Plone | =4.3.3 | |
Plone Plone | =4.3.4 | |
Plone Plone | =4.3.5 | |
Plone Plone | =4.3.6 | |
Plone Plone | =4.3.7 | |
Plone Plone | =4.3.8 | |
Plone Plone | =4.3.9 | |
Plone Plone | =4.3.10 | |
Plone Plone | =4.3.11 | |
Plone Plone | =5.0 | |
Plone Plone | =5.0-a1 | |
Plone Plone | =5.0-rc1 | |
Plone Plone | =5.0-rc2 | |
Plone Plone | =5.0-rc3 | |
Plone Plone | =5.0.1 | |
Plone Plone | =5.0.2 | |
Plone Plone | =5.0.3 | |
Plone Plone | =5.0.4 | |
Plone Plone | =5.0.5 | |
Plone Plone | =5.0.6 | |
Plone Plone | =5.1a1 | |
pip/Plone | >=3.3<=3.3.6 | |
pip/Plone | >=4.0a1<4.3.12 | 4.3.12 |
pip/Plone | >=5.0<5.0.6 | 5.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.