CVE-2016-7138

Description

Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.491

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Python-plone 3.3.6Windows
Multiple vulnerabilities are affected in Python-plone 4.3.11Windows
Multiple vulnerabilities are affected in Python-plone 5.0.6Windows
Multiple vulnerabilities are affected in Python-plone for linux 3.3.6Linux
Multiple vulnerabilities are affected in Python-plone for linux 4.3.11Linux
Multiple vulnerabilities are affected in Python-plone for linux 5.0.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234