Description
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
Remediation
References
Related Vulnerabilities
Next.js Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2024-46982)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-3011)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1570)
ProjectSend Improper Privilege Management Vulnerability (CVE-2020-28874)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-4614)