CVE-2021-33512: XSS
Published May 21, 2021
·Updated
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.
Affected Software
2 affected components
pip/Plone<=5.2.4
Plone plone<=5.2.4
Event History
May 21, 2021
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 8, 2021
Advisory Published
via GitHub·11:20 PM
Frequently Asked Questions
1
What is CVE-2021-33512?
CVE-2021-33512 is a vulnerability in Plone through version 5.2.4 that allows stored XSS attacks by a Contributor through uploading an SVG or HTML document.
2
What is the severity of CVE-2021-33512?
The severity of CVE-2021-33512 is medium with a CVSS score of 5.4.
3
How can I exploit CVE-2021-33512?
To exploit CVE-2021-33512, you can upload a malicious SVG or HTML document as a Contributor in Plone.
4
Is there a fix available for CVE-2021-33512?
Yes, a hotfix is available for CVE-2021-33512. You can find more information about the hotfix at the following link: https://plone.org/security/hotfix/20210518/stored-xss-from-file-upload-svg-html
5
Where can I find more information about CVE-2021-33512?
You can find more information about CVE-2021-33512 at the following link: http://www.openwall.com/lists/oss-security/2021/05/22/1