Description
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
Remediation
References
Related Vulnerabilities
Apache Tomcat Incorrect Default Permissions Vulnerability (CVE-2020-8022)
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17669)
PleskWin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-24044)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5204)