CVE-2016-7147: XSS
Cross-site scripting (XSS) vulnerability in the managefindResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated by the objids:tokens parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7140.
Other sources
Cross-site scripting (XSS) vulnerability in the managefindResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated by the objids:tokens parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7140.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7147?
CVE-2016-7147 is classified as a moderate severity vulnerability due to its ability to enable cross-site scripting attacks.
How do I fix CVE-2016-7147?
To fix CVE-2016-7147, upgrade to Plone version 4.3.12 or 5.0.7 or later.
What types of attacks can CVE-2016-7147 enable?
CVE-2016-7147 can enable remote attackers to inject arbitrary web scripts or HTML, leading to potential phishing or malware attacks.
What versions of Plone are affected by CVE-2016-7147?
CVE-2016-7147 affects Plone versions prior to 4.3.12 and 5.x prior to 5.0.7.
Is CVE-2016-7147 a persistent or non-persistent XSS vulnerability?
CVE-2016-7147 is classified as a non-persistent XSS vulnerability.