First published: Wed Jun 30 2021(Updated: )
In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plone Plone | >=5.0<=5.2.4 | |
pip/plone | >=5.0<=5.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Plone vulnerability is CVE-2021-35959.
The severity of CVE-2021-35959 is medium with a severity value of 5.4.
Editors in Plone 5.0 through 5.2.4 can be affected by CVE-2021-35959 if a Contributor has created a folder with a SCRIPT tag in the description field.
Yes, there are known references for CVE-2021-35959. They can be found at the following URLs: http://www.openwall.com/lists/oss-security/2021/06/30/2, https://plone.org/security/hotfix/20210518/stored-xss-in-folder-contents.
Yes, a hotfix is available for CVE-2021-35959. More information on the fix can be found at https://plone.org/security/hotfix/20210518/stored-xss-in-folder-contents.