GMS-2022-46: Cross-site Scripting and Open Redirect in Products.CMFPlone
(updated )
Plone is vulnerable to reflected cross site scripting and open redirect when an attacker can get a compromised version of the image_view_fullscreen page in a cache, for example in Varnish.
References
Detect and mitigate GMS-2022-46 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →