CVE-2017-1000482: XSS
A member of the Plone 2.5-5.1rc1 site could set javascript in the homepage property of his profile, and have this executed when a visitor click the home page link on the author page.
Other sources
A member of the Plone site could set javascript in the homepage property of their profile, and have this executed when a visitor clicks the home page link on the author page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1000482?
CVE-2017-1000482 is a vulnerability in Plone that allows a member to execute JavaScript by setting the home_page property in their profile.
Which versions of Plone are affected by CVE-2017-1000482?
Plone versions 2.5-5.1rc1 are affected by CVE-2017-1000482.
What is the severity of CVE-2017-1000482?
CVE-2017-1000482 has a severity rating of 5.4 (medium).
How can I fix CVE-2017-1000482?
To fix CVE-2017-1000482, update to Plone version 5.2 or apply the hotfix provided by Plone.
Where can I find more information about CVE-2017-1000482?
You can find more information about CVE-2017-1000482 on the NVD website, Plone's security hotfix page, and the GitHub issue.