Lucene search

K
osvGoogleOSV:GHSA-V3HP-F8QR-CF3P
HistoryMay 14, 2022 - 2:45 a.m.

Plone XSS

2022-05-1402:45:59
Google
osv.dev
6
plone cms
cross-site scripting
vulnerability
remote attackers
crafted url

EPSS

0.002

Percentile

64.8%

Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

EPSS

0.002

Percentile

64.8%