CVE-2021-35959: XSS
In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Plone vulnerability?
The vulnerability ID for this Plone vulnerability is CVE-2021-35959.
What is the severity of CVE-2021-35959?
The severity of CVE-2021-35959 is medium with a severity value of 5.4.
How can Editors in Plone 5.0 through 5.2.4 be affected by CVE-2021-35959?
Editors in Plone 5.0 through 5.2.4 can be affected by CVE-2021-35959 if a Contributor has created a folder with a SCRIPT tag in the description field.
Are there any known references for CVE-2021-35959?
Yes, there are known references for CVE-2021-35959. They can be found at the following URLs: http://www.openwall.com/lists/oss-security/2021/06/30/2, https://plone.org/security/hotfix/20210518/stored-xss-in-folder-contents.
Is there a fix available for CVE-2021-35959?
Yes, a hotfix is available for CVE-2021-35959. More information on the fix can be found at https://plone.org/security/hotfix/20210518/stored-xss-in-folder-contents.