First published: Fri May 21 2021(Updated: )
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plone Plone | <=4.3.20 | |
Plone Plone | >=5.0<=5.2.4 | |
Zope Zope | <2.5.1 | |
pip/Plone | <=5.2.4 | |
pip/Products.PluggableAuthService | <2.6.2 | 2.6.2 |
pip/Products.CMFCore | <2.5.1 | 2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33507 is a vulnerability that allows Reflected XSS in Zope Products.CMFCore and Products.PluggableAuthService, as used in Plone through version 5.2.4 and other products.
CVE-2021-33507 has a severity rating of 6.1, which is considered medium.
Plone versions up to 4.3.20 and versions between 5.0 and 5.2.4, as well as Zope versions up to 2.5.1 are affected by CVE-2021-33507.
CVE-2021-33507 is associated with CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2021-33507, update Zope Products.CMFCore to version 2.5.1 or later, and update Products.PluggableAuthService to version 2.6.2 or later.