Description
Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.
Remediation
References
Related Vulnerabilities
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-32971)
WordPress Plugin Brandfolder-Digital Asset Management Simplified Local/Remote File Inclusion (3.0)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3963)
WordPress Plugin Easy2Map Photos Cross-Site Scripting (2.0.6)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1167)