Safety vulnerability ID: 25966
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Cross-site scripting (XSS) vulnerability in skins/plone_templates/default_error_message.pt in Plone before 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the type_name parameter to Members/ipa/createObject.
Latest version: 6.1.1
The Plone Content Management System
Cross-site scripting (XSS) vulnerability in skins/plone_templates/default_error_message.pt in Plone before 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the type_name parameter to Members/ipa/createObject.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application