header-logo
Suggest Exploit
vendor:
Plone CMS
by:
Piyush Patil
8.8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Plone CMS
Affected Version From: 5.2.3
Affected Version To: 5.2.3
Patch Exists: YES
Related CWE: None
CPE: a:plone:plone:5.2.3
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows 10
2021

Plone CMS 5.2.3 – ‘Title’ Stored XSS

Plone CMS 5.2.3 is vulnerable to stored XSS. An attacker can inject malicious JavaScript code in the 'Title' field of the Site Setup page. When a user visits the page, the malicious code is executed in the user's browser.

Mitigation:

The vendor has released a patch to address this vulnerability. It is recommended to upgrade to the latest version of Plone CMS.
Source

Exploit-DB raw data: