Cross-Site Scripting in Plone Site by User Profile Configuration
CVE-2017-1000482

5.4MEDIUM

Key Information:

Vendor

Plone

Status
Vendor
CVE Published:
3 October 2022

What is CVE-2017-1000482?

A vulnerability allows users of Plone versions 2.5 through 5.1rc1 to embed JavaScript in the home_page property of their profiles. When other users visit the author page and click on the home page link, this script can execute in their browsers, potentially leading to session hijacking or other malicious actions. The issue originates from insufficient validation of user input, underscoring the importance of rigorous security measures in web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.