Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-1000482


A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.


Published

2018-01-03T18:29:00.447

Last Modified

2024-11-21T03:04:49.987

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application plone plone ≤ 5.0.9 Yes
Application plone plone 5.1 Yes
Application plone plone 5.1 Yes
Application plone plone 5.1 Yes
Application plone plone 5.1 Yes
Application plone plone 5.1 Yes
Application plone plone 5.1 Yes

References