An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://plone.org/security/hotfix/20200121 | vendor advisory |
https://www.openwall.com/lists/oss-security/2020/01/22/1 | third party advisory mailing list |
https://plone.org/security/hotfix/20200121/xss-in-the-title-field-on-plone-5-0-and-higher | vendor advisory |
http://www.openwall.com/lists/oss-security/2020/01/24/1 | third party advisory mailing list |