MEDIUM 6.1 PyPI
Plone has stored XSS in folder contents
GHSA-qfhw-fv3g-v836 · CVE-2021-35959 · PYSEC-2021-110
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-35959
- PACKAGE https://github.com/plone/Plone
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-110.yaml
- WEB https://plone.org/security/hotfix/20210518/stored-xss-in-folder-contents
- WEB http://www.openwall.com/lists/oss-security/2021/06/30/2
Ready to move
Start Securing
Free, no credit card | First findings in minutes