Executive brief
Plone is a content management system used to build and manage websites and intranets. This vulnerability allows attackers to inject malicious scripts into web forms via specially crafted requests, enabling them to steal user credentials, redirect users to malicious sites, or deface website content when users interact with affected pages.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the z3c.form component of Plone CMS, classified under CWE-79. It affects versions 4.x through 4.3.11 and 5.x through 5.0.6, and can be triggered by crafting a malicious GET request to the application. The vulnerability requires user interaction—a victim must click on or visit a malicious link—but does not require prior authentication or special privileges. An attacker can execute arbitrary JavaScript in a victim's browser session, potentially compromising session tokens, stealing sensitive data, or performing actions on behalf of the user. A fix was available in a security hotfix released on 2016-08-30.
Affected products
- Plone Plone 4.0.0 through 4.3.11 and 5.0.0 through 5.0.6
Timeline
- 2016-09: disclosed: Initial public disclosure
- 2022-05-14: advisory: GHSA-22jm-p2vv-j2hc published
- 2016-08-30: patched: Security hotfix released