First published: Thu Jan 18 2024(Updated: )
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting version below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
Credit: cve-coordination@incibe.es cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Plone | <=6.0.5 | 6.0.7 |
Plone Plone | <6.0.7 |
The manufacturer has fixed the vulnerability in version 6.0.7.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.