Plone CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-1000482 - Vulnerability Database
Plone CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-1000482
Medium
Reference:
CVE-2017-1000482
Title:
Plone CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile and have this executed when a visitor click the home page link on the author page.