Description
Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contact Form Generator Multiple Cross-Site Request Forgery Vulnerabilities (2.1.86)
PHP Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2014-5459)
WordPress Plugin myLinksDump 'url' Parameter SQL Injection (1.2)