vendor:
Plone CMS
by:
Piyush Patil
8.8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Plone CMS
Affected Version From: 5.2.3
Affected Version To: 5.2.3
Patch Exists: YES
Related CWE: None
CPE: a:plone:plone:5.2.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2021
Plone CMS 5.2.3 – ‘Title’ Stored XSS
Plone CMS 5.2.3 is vulnerable to stored XSS. An attacker can inject malicious JavaScript code in the 'Title' field of the Site Setup page. When a user visits the page, the malicious code is executed in the user's browser.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to upgrade to the latest version of Plone CMS.