CVE-2021-33508: XSS
Published May 21, 2021
·Updated
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.
Affected Software
2 affected components
pip/Plone<=5.2.4
Plone plone<=5.2.4
Event History
May 21, 2021
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
Description
Jun 8, 2021
Advisory Published
via GitHub·11:20 PM
Frequently Asked Questions
1
What is CVE-2021-33508?
CVE-2021-33508 is a vulnerability in Plone through 5.2.4 that allows XSS attacks via a mishandled full name during rendering of the ownership tab of a content item.
2
How does CVE-2021-33508 affect Plone?
CVE-2021-33508 affects Plone versions up to and including 5.2.4.
3
What is the severity of CVE-2021-33508?
CVE-2021-33508 has a severity rating of medium with a CVSS score of 5.4.
4
How can an attacker exploit CVE-2021-33508?
An attacker can exploit CVE-2021-33508 by injecting malicious code into the full name field of a content item, which is mishandled and renders as XSS.
5
Is there a fix available for CVE-2021-33508?
Yes, a hotfix is available for CVE-2021-33508 on the Plone website.