Cross-Site Scripting Vulnerability in Plone by Plone Foundation
CVE-2021-35959
5.4MEDIUM
What is CVE-2021-35959?
In Plone versions 5.0 through 5.2.4, a cross-site scripting (XSS) vulnerability exists that allows Editors to be exploited via a maliciously crafted folder description. Specifically, if a Contributor embeds a SCRIPT tag in the description field of a folder, it may lead to execution of arbitrary scripts. This vulnerability can expose sensitive user data and compromise the integrity of the application.
