CVE-2021-3313

Description

Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The users input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript in the context of the victims browser if the victim opens a vulnerable page containing an XSS payload.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.444

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-3313 are fixed in Python-plone 5.2.4Windows
Vulnerabilities CVE-2021-29002,CVE-2021-3313 are affected in Python-plone 5.2.3Windows
Vulnerabilities CVE-2021-3313 are fixed in Python-plone for linux 5.2.4Linux
Vulnerabilities CVE-2021-29002,CVE-2021-3313 are affected in Python-plone for linux 5.2.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234