Cross-Site Scripting in Plone Site by User Profile Configuration
CVE-2017-1000482
5.4MEDIUM
What is CVE-2017-1000482?
A vulnerability allows users of Plone versions 2.5 through 5.1rc1 to embed JavaScript in the home_page property of their profiles. When other users visit the author page and click on the home page link, this script can execute in their browsers, potentially leading to session hijacking or other malicious actions. The issue originates from insufficient validation of user input, underscoring the importance of rigorous security measures in web applications.
