Description
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
Remediation
References
Related Vulnerabilities
WordPress Plugin Elementor Website Builder Arbitrary File Upload (3.18.1)
Drupal Core 7.x Security Bypass (7.0 - 7.68)
WordPress Plugin Remove WP Update Nags Security Bypass (1.3.0)
SugarCRM CVE-2023-35809 Vulnerability (CVE-2023-35809)
WordPress Plugin Product Import Export for WooCommerce Cross-Site Request Forgery (1.7.4)