CVE-2010-2422

Plone 2.1-3.3.4 - Cross-Site Scripting via Safe HTML Transform

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40270
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/40999

Scores

EPSS 0.0123
EPSS Percentile 65.7%

Details

CWE
CWE-79
Status published
Products (37)
plone/plone 2.1
plone/plone 2.1.1
plone/plone 2.1.2
plone/plone 2.1.3
plone/plone 2.1.4
plone/plone 2.5
plone/plone 2.5.1
plone/plone 2.5.2
plone/plone 2.5.3
plone/plone 2.5.4
... and 27 more
Published Jun 24, 2010
Tracked Since Feb 18, 2026