Description Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses. Remediation References CVE-2015-7318 Related Vulnerabilities WordPress Plugin Social Connect Cross-Site Scripting (1.0.4) WordPress Plugin Store Locator Plus for WordPress Cross-Site Scripting (4.5.10) WordPress Plugin WP Statistics Cross-Site Scripting (8.3) OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3732) Ruby CVE-2019-15845 Vulnerability (CVE-2019-15845) Severity High Classification CVE-2015-7318 CWE-20 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Tags Missing Update Known Vulnerabilities