Lucene search

K
githubGitHub Advisory DatabaseGHSA-35RG-466W-77H3
HistoryJun 18, 2021 - 6:44 p.m.

Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone

2021-06-1818:44:50
CWE-79
GitHub Advisory Database
github.com
73
cross-site scripting
reflected xss
zope
plone
cmfcore
pluggableauthservice

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

36.1%

Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.

Affected configurations

Vulners
Node
ploneploneRange5.2.4
OR
zopeproducts.pluggableauthserviceRange<2.6.2
OR
zopeproducts.cmfcoreRange<2.5.1
VendorProductVersionCPE
ploneplone*cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*
zopeproducts.pluggableauthservice*cpe:2.3:a:zope:products.pluggableauthservice:*:*:*:*:*:*:*:*
zopeproducts.cmfcore*cpe:2.3:a:zope:products.cmfcore:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

36.1%

Related for GHSA-35RG-466W-77H3