First published: Wed Jan 03 2018(Updated: )
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plone Plone | <=5.0.9 | |
Plone Plone | =5.1-a1 | |
Plone Plone | =5.1-a2 | |
Plone Plone | =5.1-b2 | |
Plone Plone | =5.1-b3 | |
Plone Plone | =5.1-b4 | |
Plone Plone | =5.1-rc1 | |
pip/Products.CMFPlone | >=5.1a1<5.1.0 | 5.1.0 |
pip/Products.CMFPlone | >=5.0.0<5.0.10 | 5.0.10 |
pip/Products.CMFPlone | <4.3.17 | 4.3.17 |
pip/Plone | >=5.0a1<5.1.0 | 5.1.0 |
pip/Plone | >=2.5a1<4.3.16 | 4.3.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000482 is a vulnerability in Plone that allows a member to execute JavaScript by setting the home_page property in their profile.
Plone versions 2.5-5.1rc1 are affected by CVE-2017-1000482.
CVE-2017-1000482 has a severity rating of 5.4 (medium).
To fix CVE-2017-1000482, update to Plone version 5.2 or apply the hotfix provided by Plone.
You can find more information about CVE-2017-1000482 on the NVD website, Plone's security hotfix page, and the GitHub issue.