plone plone CVE-2021-3313 is a vulnerability in Plone
Published on May 20, 2021

Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript in the context of the victim's browser if the victim opens a vulnerable page containing an XSS payload.

NVD


Products Associated with CVE-2021-3313

Want to know whenever a new CVE is published for Plone? stack.watch will email you.

 

Exploit Probability

EPSS
0.44%
Percentile
62.98%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.