Description
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
Remediation
References
Related Vulnerabilities
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-42130)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-28566)
WordPress Plugin ByREV WP-PICShield Cross-Site Request Forgery (1.9.7)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-31547)