Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xfx-55x4-j223

Опубликовано: 18 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Cross-Frame Scripting vulnerability has been found on Plone CMS

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting version below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

<= 6.0.5

6.0.7

EPSS

Процентиль: 15%
0.0005
Низкий

7.1 High

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.3
nvd
около 2 лет назад

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.

EPSS

Процентиль: 15%
0.0005
Низкий

7.1 High

CVSS3

Дефекты

CWE-1021