Description
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.
Remediation
References
Related Vulnerabilities
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3170)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-35151)
WordPress Plugin WP Mobile Detector Arbitrary File Upload (3.5)
MySQL Other Vulnerability (CVE-2007-5970)
WordPress Plugin My Calendar Multiple Cross-Site Scripting Vulnerabilities (1.10.1)