Safety vulnerability ID: 53661
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Products.cmfdifftool 3.3.3 includes a fix for a XSS vulnerability.
https://plone.org/security/hotfix/20210518/xss-vulnerability-in-cmfdifftool
Latest version: 4.0.4
Diff tool for Plone
------------------
Bug fixes:
- Added XSS fix from PloneHotfix20210518 for inline diff.
See `vulnerability <https://plone.org/security/hotfix/20210518/xss-vulnerability-in-cmfdifftool>`_.
The first version of the hotfix escaped all html.
Now for the rich text field, use the safe html transform, otherwise the inline diff is no longer inline.
[maurits] (39)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application