First published: Fri May 21 2021(Updated: )
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plone Plone | <=5.2.4 | |
pip/Plone | <=5.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33508 is a vulnerability in Plone through 5.2.4 that allows XSS attacks via a mishandled full name during rendering of the ownership tab of a content item.
CVE-2021-33508 affects Plone versions up to and including 5.2.4.
CVE-2021-33508 has a severity rating of medium with a CVSS score of 5.4.
An attacker can exploit CVE-2021-33508 by injecting malicious code into the full name field of a content item, which is mishandled and renders as XSS.
Yes, a hotfix is available for CVE-2021-33508 on the Plone website.