Bug: Plone XSS and permission errors (WLB-2011060105 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Plone XSS and permission errors
 Credit: matthew matthewwilkes
 Date: 2011.06.09
 CWE: CWE-79 (Show similar)
CWE-264 (Show similar)
 CVE: CVE-2011-1948 (Show details)
CVE-2011-1949 (Show details)
CVE-2011-1950 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
No
Yes

As a member of the Plone security response team I hereby notify you that we have been made aware of three distinct
security holes in Plone and are requesting CVE identifiers.

1. Reflected XSS attack
A crafted URL can display arbitrary HTML output

2. Persistent XSS attack
Certain valid HTML will allow Javascript filtering to be bypassed.

3. Unauthorised data changes
One change form for data allows preferences to be changed. No deletion of content of loss of confidentiality is
possible.

Thanks very much,

Matthew

References:

http://plone.org/products/plone/security/advisories/CVE-2011-1950
http://xforce.iss.net/xforce/xfdb/67695
http://www.securityfocus.com/bid/48005
http://www.securityfocus.com/archive/1/archive/1/518155/100/0/threaded
http://secunia.com/advisories/44775

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com