-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Plone | pip | >= 5.0, < 5.0.6 | 5.0.6 |
| Plone | pip | >= 4.0a1, < 4.3.12 | 4.3.12 |
| Plone | pip | >= 3.3, <= 3.3.6 |
The vulnerability stems from improper input sanitization in multiple Plone page templates and forms. Key evidence includes:
While exact file paths aren't provided in disclosures, the pattern matches Plone's template-based architecture and known XSS vectors in parameter handling. High confidence in the login_form template due to its direct exposure to unauthenticated users and common 'next' parameter misuse.
A Semantic Attack on Google Gemini - Read the Latest Research