Plone CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-35959 - Vulnerability Database
Plone CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-35959
Medium
Reference:
CVE-2021-35959
Title:
Plone CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In Plone 5.0 through 5.2.4 Editors are vulnerable to XSS in the folder contents view if a Contributor has created a folder with a SCRIPT tag in the description field.