GHSA-qj7x-wm9q-qjx8, CVE-2010-2422
pypi/Plone
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
All versions starting from 2.1 up to 3.3.5
Upgrade to version 3.3.6 or above.
2024-02-09
source |