VYPR
Medium severity5.4NVD Advisory· Published Jan 3, 2018· Updated Jun 17, 2026

CVE-2017-1000482

CVE-2017-1000482

Description

A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Products.CMFPlonePyPI
< 4.3.174.3.17
Products.CMFPlonePyPI
>= 5.0.0, < 5.0.105.0.10
Products.CMFPlonePyPI
>= 5.1a1, < 5.1.05.1.0
PlonePyPI
>= 2.5a1, < 4.3.164.3.16
PlonePyPI
>= 5.0a1, < 5.1.05.1.0

Affected products

9
  • cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*range: <=5.0.9
    • cpe:2.3:a:plone:plone:5.1:a1:*:*:*:*:*:*
    • cpe:2.3:a:plone:plone:5.1:a2:*:*:*:*:*:*
    • cpe:2.3:a:plone:plone:5.1:b2:*:*:*:*:*:*
    • cpe:2.3:a:plone:plone:5.1:b3:*:*:*:*:*:*
    • cpe:2.3:a:plone:plone:5.1:b4:*:*:*:*:*:*
    • cpe:2.3:a:plone:plone:5.1:rc1:*:*:*:*:*:*
  • ghsa-coords2 versions
    >= 2.5a1, < 4.3.16+ 1 more
    • (no CPE)range: >= 2.5a1, < 4.3.16
    • (no CPE)range: < 4.3.17

Patches

Vulnerability mechanics

References

13

News mentions

0

No linked articles in our index yet.