Stored Cross-Site Scripting Vulnerability in Plone CMS by Plone Foundation
CVE-2021-3313
5.4MEDIUM
What is CVE-2021-3313?
The Plone CMS is susceptible to a stored Cross-Site Scripting (XSS) vulnerability affecting versions up to 5.2.4. An attacker can exploit this vulnerability through the user fullname property and file upload functionality, where user input data is improperly encoded and subsequently rendered as executable code by the browser. This enables attackers to execute malicious JavaScript within the context of the victim's browser, particularly when the victim accesses a compromised page containing an XSS payload.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
