Junglewise Threat Intelligence

CVE-2021-29002: PYSEC-2021-889 - A stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in site-controlpanel via the "form.widgets.site_title" parameter

CVE-2021-29002 · Severity: low · CVSS 3.1 · Published 2021-03-24

Technologies: Plone, plone (PyPI). Vendors: Plone, PyPI.

Executive brief

Plone is a popular open-source content management system used to build and manage websites. A stored cross-site scripting (XSS) vulnerability in the site control panel's title field allows authenticated administrators to inject malicious code that executes in the browsers of other users viewing the site. An attacker with admin access could steal session cookies, credentials, or execute unauthorized actions on behalf of users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the site control panel of Plone CMS, specifically in the form.widgets.site_title parameter used to set the site title. The vulnerability stems from insufficient output encoding/sanitization of the site title value when it is rendered on pages. An authenticated user with manager privileges can inject arbitrary JavaScript code through the Site Setup interface, which is then persistently stored and executed in the browsers of all users viewing the affected site. An attacker must have valid admin credentials to exploit this vulnerability. The injected payload persists and executes each time the site title is displayed, making it a high-impact stored XSS attack.

Affected products

  • Plone Plone 3.0 through 5.2.3

Timeline

  • 2021-03-24: disclosed
  • 2022-05-24: advisory

References

Related threats