Safety vulnerability ID: 40533
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.
Latest version: 6.1.1
The Plone Content Management System
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item. See CVE-2021-33508.
MISC:https://plone.org/security/hotfix/20210518/stored-xss-from-user-fullname: https://plone.org/security/hotfix/20210518/stored-xss-from-user-fullname
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application