CVE-2024-0669: Cross-Frame Scripting (XFS) on Plone CMS
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting version below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
Other sources
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0669?
CVE-2024-0669 is classified as a moderate severity Cross-Frame Scripting vulnerability affecting Plone CMS versions below 6.0.5.
How do I fix CVE-2024-0669?
To resolve CVE-2024-0669, upgrade Plone CMS to version 6.0.7 or later.
Who is affected by CVE-2024-0669?
CVE-2024-0669 affects installations of Plone CMS running versions earlier than 6.0.5.
What type of vulnerability is CVE-2024-0669?
CVE-2024-0669 is a Cross-Frame Scripting vulnerability that allows the execution of malicious iframe elements.
What could an attacker do with CVE-2024-0669?
An attacker could leverage CVE-2024-0669 to store a malicious URL that might be opened by an administrator, resulting in potential exploitation.