CVE-2010-2422

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pypi/Plone

Identifiers

GHSA-qj7x-wm9q-qjx8, CVE-2010-2422

Package Slug

pypi/Plone

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.

Affected Versions

All versions starting from 2.1 up to 3.3.5

Solution

Upgrade to version 3.3.6 or above.

Last Modified

2024-02-09

source