A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
2018-01-03T18:29:00.447
2024-11-21T03:04:49.987
Modified
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | plone | plone | ≤ 5.0.9 | Yes |
| Application | plone | plone | 5.1 | Yes |
| Application | plone | plone | 5.1 | Yes |
| Application | plone | plone | 5.1 | Yes |
| Application | plone | plone | 5.1 | Yes |
| Application | plone | plone | 5.1 | Yes |
| Application | plone | plone | 5.1 | Yes |