Description
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The manufacturer has fixed the vulnerability in version 6.0.7.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0263 | A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element. |
Github GHSA |
GHSA-5xfx-55x4-j223 | Cross-Frame Scripting vulnerability has been found on Plone CMS |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-17T21:19:21.757Z
Reserved: 2024-01-18T08:26:22.410Z
Link: CVE-2024-0669
No data.
Status : Modified
Published: 2024-01-18T13:15:09.177
Modified: 2024-11-21T08:47:06.537
Link: CVE-2024-0669
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA