Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h6hq-c896-w882

Опубликовано: 23 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 5.4

Описание

Plone Cross-site Scripting vulnerability

Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 3.3.2, < 3.3.6

3.3.6

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.0a0, < 4.0.6

4.0.6

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.1a0, < 4.1.1

4.1.1

EPSS

Процентиль: 58%
0.00373
Низкий

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.

redhat
больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.

nvd
больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.

debian
больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the safe_html filter in Pr ...

EPSS

Процентиль: 58%
0.00373
Низкий

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79