MEDIUM 5.4 PyPI
Products.CMFPlone XSS in profile home_page property
GHSA-859j-668v-mrr6 · CVE-2017-1000482 · PYSEC-2018-71 · PYSEC-2026-2962
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A member of the Plone site could set javascript in the home_page property of their profile, and have this executed when a visitor clicks the home page link on the author page.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2017-1000482
- WEB https://github.com/plone/Products.CMFPlone/issues/2232
- WEB https://github.com/plone/Products.CMFPlone/pull/2233
- WEB https://github.com/plone/Products.CMFPlone/pull/2234
- WEB https://github.com/plone/Products.CMFPlone/pull/2235
- WEB https://github.com/plone/Products.CMFPlone/pull/2236
- WEB https://github.com/plone/Products.CMFPlone/commit/05a943ecbcdda56bacc93b55c9e2e908d8a7dfab
- WEB https://github.com/plone/Products.CMFPlone/commit/0e50e1e67ea3b6d3187f78cb1a1628081f654d3b
- WEB https://github.com/plone/Products.CMFPlone/commit/236b62b756ff46a92783b3897e717dfb15eb07d8
- WEB https://github.com/plone/Products.CMFPlone/commit/7db5b2c8fb684055987b8c4fdedc29289bd26373
- PACKAGE https://github.com/plone/Products.CMFPlone
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2018-71.yaml
- WEB https://plone.org/security/hotfix/20171128/xss-using-the-home_page-member-property
Ready to move
Start Securing
Free, no credit card | First findings in minutes