Safety vulnerability ID: 37785
The information on this page was manually curated by our Cybersecurity Intelligence Team.
An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site. See: CVE-2020-7937.
Latest version: 6.1.1
The Plone Content Management System
An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.
MISC:https://plone.org/security/hotfix/20200121: https://plone.org/security/hotfix/20200121
MISC:https://plone.org/security/hotfix/20200121/xss-in-the-title-field-on-plone-5-0-and-higher: https://plone.org/security/hotfix/20200121/xss-in-the-title-field-on-plone-5-0-and-higher
MISC:https://www.openwall.com/lists/oss-security/2020/01/22/1: https://www.openwall.com/lists/oss-security/2020/01/22/1
MLIST:[oss-security] 20200124 Re: Plone security hotfix 20200121: http://www.openwall.com/lists/oss-security/2020/01/24/1
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application