Description
In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.
Remediation
References
Related Vulnerabilities
math.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-1001002)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1428)
WordPress Plugin Analytics-Gtag Restricted File Upload (1.8.1)
Oracle Application Server CVE-2006-0435 Vulnerability (CVE-2006-0435)