CVE-2016-7136

z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
ploneplone
4.0
ploneplone
4.0.1
ploneplone
4.0.2
ploneplone
4.0.3
ploneplone
4.0.4
ploneplone
4.0.5
ploneplone
4.0.7
ploneplone
4.0.8
ploneplone
4.0.9
ploneplone
4.0.10
ploneplone
4.1
ploneplone
4.1.1
ploneplone
4.1.2
ploneplone
4.1.3
ploneplone
4.1.4
ploneplone
4.1.5
ploneplone
4.1.6
ploneplone
4.2
ploneplone
4.2.1
ploneplone
4.2.2
ploneplone
4.2.3
ploneplone
4.2.4
ploneplone
4.2.5
ploneplone
4.2.6
ploneplone
4.2.7
ploneplone
4.3
ploneplone
4.3.1
ploneplone
4.3.2
ploneplone
4.3.3
ploneplone
4.3.4
ploneplone
4.3.5
ploneplone
4.3.6
ploneplone
4.3.7
ploneplone
4.3.8
ploneplone
4.3.9
ploneplone
4.3.10
ploneplone
4.3.11
ploneplone
5.0
ploneplone
5.0:a1
ploneplone
5.0:rc1
ploneplone
5.0:rc2
ploneplone
5.0:rc3
ploneplone
5.0.1
ploneplone
5.0.2
ploneplone
5.0.3
ploneplone
5.0.4
ploneplone
5.0.5
ploneplone
5.0.6
ploneplone
5.1a1:a1
𝑥
= Vulnerable software versions