Safety vulnerability ID: 35689
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone 4.3.12 and 5.0.7 include a fix for CVE-2016-7147: Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated by the obj_ids:tokens parameter.
NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7140.
Latest version: 6.1.1
The Plone Content Management System
Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated by the obj_ids:tokens parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7140.
MISC:https://plone.org/security/hotfix/20170117: https://plone.org/security/hotfix/20170117
MISC:https://plone.org/security/hotfix/20170117/non-persistent-xss-in-zope2: https://plone.org/security/hotfix/20170117/non-persistent-xss-in-zope2
MISC:https://www.curesec.com/blog/article/blog/Plone-XSS-186.html: https://www.curesec.com/blog/article/blog/Plone-XSS-186.html
BID:96117: http://www.securityfocus.com/bid/96117
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application