{"id":"CVE-2017-1000482","aliases":["GHSA-859j-668v-mrr6","PYSEC-2018-71","PYSEC-2026-2962"],"title":"Products.CMFPlone XSS in profile home_page property","summary":"Products.CMFPlone XSS in profile home_page property","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","vendor":"products-cmfplone","product":"products-cmfplone","ecosystem":"pip","affected":["products-cmfplone < 4.3.17","products-cmfplone >= 5.0.0, < 5.0.10","products-cmfplone >= 5.1a1, < 5.1.0","plone >= 2.5a1, < 4.3.16","plone >= 5.0a1, < 5.1.0"],"patched":["products-cmfplone 4.3.17","products-cmfplone 5.0.10","products-cmfplone 5.1.0","plone 4.3.16","plone 5.1.0"],"published":"2022-05-14","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-859j-668v-mrr6","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000482"},{"url":"https://github.com/plone/Products.CMFPlone/issues/2232"},{"url":"https://github.com/plone/Products.CMFPlone/pull/2233"},{"url":"https://github.com/plone/Products.CMFPlone/pull/2234"},{"url":"https://github.com/plone/Products.CMFPlone/pull/2235"},{"url":"https://github.com/plone/Products.CMFPlone/pull/2236"},{"url":"https://github.com/plone/Products.CMFPlone/commit/05a943ecbcdda56bacc93b55c9e2e908d8a7dfab"},{"url":"https://github.com/plone/Products.CMFPlone/commit/0e50e1e67ea3b6d3187f78cb1a1628081f654d3b"},{"url":"https://github.com/plone/Products.CMFPlone/commit/236b62b756ff46a92783b3897e717dfb15eb07d8"},{"url":"https://github.com/plone/Products.CMFPlone/commit/7db5b2c8fb684055987b8c4fdedc29289bd26373"},{"url":"https://github.com/plone/Products.CMFPlone"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2018-71.yaml"},{"url":"https://plone.org/security/hotfix/20171128/xss-using-the-home_page-member-property"}],"tags":["osv","pip"],"epss":0.00689,"epssPercentile":0.5094,"ingestedAt":"2026-07-13T18:57:54.819Z","slug":"CVE-2017-1000482","body":"## Overview\n\nA member of the Plone site could set javascript in the `home_page` property of their profile, and have this executed when a visitor clicks the home page link on the author page.\n\n## Affected packages\n\n- `products-cmfplone < 4.3.17`\n- `products-cmfplone >= 5.0.0, < 5.0.10`\n- `products-cmfplone >= 5.1a1, < 5.1.0`\n- `plone >= 2.5a1, < 4.3.16`\n- `plone >= 5.0a1, < 5.1.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `products-cmfplone 4.3.17`\n- `products-cmfplone 5.0.10`\n- `products-cmfplone 5.1.0`\n- `plone 4.3.16`\n- `plone 5.1.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}