CVE-2016-7139: XSS
Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7139?
CVE-2016-7139 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-7139?
To fix CVE-2016-7139, upgrade Plone CMS to version 4.3.12 or 5.0.6 or later.
What versions of Plone CMS are affected by CVE-2016-7139?
CVE-2016-7139 affects Plone CMS versions 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6.
What types of attacks does CVE-2016-7139 allow?
CVE-2016-7139 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Is there a workaround for CVE-2016-7139?
There is no official workaround for CVE-2016-7139; upgrading to a patched version is the recommended solution.