Описание
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.0.7 (исключая)
cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.0005
Низкий
6.3 Medium
CVSS3
7.1 High
CVSS3
Дефекты
CWE-1021
Связанные уязвимости
CVSS3: 7.1
github
около 2 лет назад
Cross-Frame Scripting vulnerability has been found on Plone CMS
EPSS
Процентиль: 15%
0.0005
Низкий
6.3 Medium
CVSS3
7.1 High
CVSS3
Дефекты
CWE-1021