Description
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
Remediation
References
Related Vulnerabilities
Drupal Core 8.9.x Multiple Cross-Site Scripting Vulnerabilities (8.9.0 - 8.9.5)
Apache Tomcat Incorrect Default Permissions Vulnerability (CVE-2020-8022)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0096)
WordPress 4.1.x Prototype Pollution (4.1 - 4.1.34)
WordPress 'index.php' Cross-Site Scripting Vulnerability (1.5)