Total vulnerabilities in the database
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
Software | From | Fixed in |
---|---|---|
plone / plone | 5.1-a1 | 5.1-a1.x |
plone / plone | 5.1-a2 | 5.1-a2.x |
plone / plone | 5.1-rc1 | 5.1-rc1.x |
plone / plone | 5.1-b4 | 5.1-b4.x |
plone / plone | 5.1-b3 | 5.1-b3.x |
plone / plone | 5.1-b2 | 5.1-b2.x |
plone / plone | - | 5.0.9.x |