Description Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses. Remediation References CVE-2015-7318 Related Vulnerabilities XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31985) PostgreSQL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-39417) ReviveAdserver Session Fixation Vulnerability (CVE-2017-5831) PHP Numeric Errors Vulnerability (CVE-2007-1383) WordPress Plugin WooCommerce Salesforce Integration Cross-Site Scripting (1.5.8) Severity High Classification CVE-2015-7318 CWE-20 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Tags Missing Update Known Vulnerabilities