Description
z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.
Remediation
References
Related Vulnerabilities
WordPress Plugin AdKlick Advertising Management Unspecified Vulnerability (1.1)
WordPress Plugin Ultimate WordPress Auction Cross-Site Request Forgery (1.0.0)
PHP Other Vulnerability (CVE-2002-0253)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-15081)
WordPress Plugin Contact Form 7 Arbitrary File Upload (3.5.3)