Safety vulnerability ID: 40537
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.
Latest version: 6.1.1
The Plone Content Management System
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document. See CVE-2021-33512.
MISC:https://plone.org/security/hotfix/20210518/stored-xss-from-file-upload-svg-html: https://plone.org/security/hotfix/20210518/stored-xss-from-file-upload-svg-html
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application