CVE-2013-7062
MEDIUMPlone 3.3.0-3.3.6 - Cross-Site Scripting via browser_id_manager or OFS.Image Method
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2, allow remote attackers to inject arbitrary web script or HTML via unspecified input in the (1) browser_id_manager or (2) OFS.Image method.
References (6)
Core 6
Core References
Vendor Advisory x_refsource_confirm
https://plone.org/security/20131210/zope-xss-in-OFS
Vendor Advisory x_refsource_confirm
https://plone.org/security/20131210/zope-xss-in-browseridmanager
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/oss-sec/2013/q4/467
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/oss-sec/2013/q4/485
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/89623
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/89627
Scores
CVSS v3
6.1
EPSS
0.0140
EPSS Percentile
69.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
plone/plone
3.3.0 - 3.3.6
pypi/Plone
3.3 - 3.3.6PyPI
Published
Jan 02, 2020
Tracked Since
Feb 18, 2026