CVE-2017-1000482Medium· 5.4▾ SunlitProducts.CMFPlone XSS in profile home_page property
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.7%
A member of the Plone site could set javascript in the home_page property of their profile, and have this executed when a visitor clicks the home page link on the author page.
products-cmfplone < 4.3.17products-cmfplone >= 5.0.0, < 5.0.10products-cmfplone >= 5.1a1, < 5.1.0plone >= 2.5a1, < 4.3.16plone >= 5.0a1, < 5.1.0Upgrade to a patched release:
products-cmfplone 4.3.17products-cmfplone 5.0.10products-cmfplone 5.1.0plone 4.3.16plone 5.1.0Connected by shared product, vendor, weakness, or advisory.