Description
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
Remediation
References
Related Vulnerabilities
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3231)
Feed Changer & Remover Cross-Site Scripting (0.2)
Photo Gallery, Images, Slider in Rbs Image Gallery Cross-Site Request Forgery (3.2.9)
Google Analytics MU Cross-Site Request Forgery (2.3.1)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33327)