A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0263 | A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by an administrator and execute a malicios iframe element. |
Github GHSA |
GHSA-5xfx-55x4-j223 | Cross-Frame Scripting vulnerability has been found on Plone CMS |
Fixes
Solution
The manufacturer has fixed the vulnerability in version 6.0.7.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-17T21:19:21.757Z
Reserved: 2024-01-18T08:26:22.410Z
Link: CVE-2024-0669
No data.
Status : Modified
Published: 2024-01-18T13:15:09.177
Modified: 2024-11-21T08:47:06.537
Link: CVE-2024-0669
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA