CVE-2021-35959
MEDIUMPlone 5.0-5.2.4 - Stored Cross-Site Scripting in Folder Description Field
Title source: llmDescription
In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://plone.org/security/hotfix/20210518/stored-xss-in-folder-contents
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/06/30/2
Scores
CVSS v3
5.4
EPSS
0.0054
EPSS Percentile
41.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
plone/plone
5.0 - 5.2.4
pypi/Plone
5.0PyPI
Published
Jun 30, 2021
Tracked Since
Feb 18, 2026