QID 997212
Date Published: 2024-02-12
QID 997212: Python (Pip) Security Update for Plone (GHSA-qj7x-wm9q-qjx8)
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.5 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qj7x-wm9q-qjx8 for updates and patch information.
Vendor References
- GHSA-qj7x-wm9q-qjx8 -
github.com/advisories/GHSA-qj7x-wm9q-qjx8
CVEs related to QID 997212
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qj7x-wm9q-qjx8 | Plone |
|