GHSA-859j-668v-mrr6

    Dashboard / Vulnerabilities / GHSA-859j-668v-mrr6

    GHSA-859j-668v-mrr6

    Published: 14 May 2022Last Modified: 13 Jul 2026

    Summary: Products.CMFPlone XSS in profile home_page property

    Details: A member of the Plone site could set javascript in the `home_page` property of their profile, and have this executed when a visitor clicks the home page link on the author page.

    Affected packages

    Package

    Name: products-cmfplone

    Purl: pkg:pypi/products-cmfplone

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.3.17

    Affected versions

    4.0b1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High