GHSA-859j-668v-mrr6

Suggest an improvement
Source
https://github.com/advisories/GHSA-859j-668v-mrr6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-859j-668v-mrr6/GHSA-859j-668v-mrr6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-859j-668v-mrr6
Aliases
Published
2022-05-14T03:49:57Z
Modified
2024-02-16T08:10:36.981866Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Products.CMFPlone XSS in profile home_page property
Details

A member of the Plone site could set javascript in the home_page property of their profile, and have this executed when a visitor clicks the home page link on the author page.

References

Affected packages

PyPI / products-cmfplone

Package

Name
products-cmfplone
View open source insights on deps.dev
Purl
pkg:pypi/products-cmfplone

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.17

Affected versions

4.*

4.0b1
4.1a1
4.1a2
4.1a3
4.1b1
4.1b2
4.1rc2
4.1rc3
4.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.2a1
4.2a2
4.2b1
4.2b2
4.2rc1
4.2rc2
4.2
4.2.0.1
4.2.1
4.2.1.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3a1
4.3a2
4.3b1
4.3b2
4.3rc1
4.3
4.3.1
4.3.2
4.3.3
4.3.4
4.3.4.1
4.3.5
4.3.6
4.3.7
4.3.8rc1
4.3.8
4.3.9
4.3.10rc1
4.3.10
4.3.11
4.3.12
4.3.13
4.3.14
4.3.15
4.3.16

PyPI / products-cmfplone

Package

Name
products-cmfplone
View open source insights on deps.dev
Purl
pkg:pypi/products-cmfplone

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.0.10

Affected versions

5.*

5.0
5.0.1
5.0.2
5.0.3rc1
5.0.3
5.0.3.1
5.0.4rc1
5.0.4
5.0.5rc1
5.0.5rc2
5.0.5
5.0.6rc1
5.0.6
5.0.7
5.0.8
5.0.9
5.0.10rc1

PyPI / products-cmfplone

Package

Name
products-cmfplone
View open source insights on deps.dev
Purl
pkg:pypi/products-cmfplone

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1a1
Fixed
5.1.0

Affected versions

5.*

5.1a1
5.1a2
5.1b2
5.1b3
5.1b4
5.1rc1
5.1rc2