Plone XSS in Zope ZMI
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Oct 18, 2024
Package
Affected versions
>= 4.0, <= 4.3.11
>= 5.0, <= 5.0.6
Patched versions
4.3.12
5.0.7
Description
Published by the National Vulnerability Database
Feb 4, 2017
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 22, 2024
Last updated
Oct 18, 2024
Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated by the
obj_ids:tokens
parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7140.References