{"id":"GHSA-p7h9-vf92-5fj5","summary":"Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool","details":"Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.","aliases":["CVE-2011-1948","PYSEC-2011-14","PYSEC-2026-2965","PYSEC-2026-2966"],"modified":"2026-07-13T16:43:05.701859834Z","published":"2018-07-23T19:50:57Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:48:29Z","nvd_published_at":"2011-06-06T19:55:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1948"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2012:0151"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2011-1948"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=711494"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/67693"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-p7h9-vf92-5fj5"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-14.yaml"},{"type":"WEB","url":"http://plone.org/products/plone/security/advisories/CVE-2011-1948"}],"affected":[{"package":{"name":"products-passwordresettool","ecosystem":"PyPI","purl":"pkg:pypi/products-passwordresettool"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.6"}]}],"versions":["1.1","1.2","1.3","1.4","2.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0a1","2.0b1","2.0b2","2.0b3","2.0b4","2.0b5","2.0b6","2.0b7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-p7h9-vf92-5fj5/GHSA-p7h9-vf92-5fj5.json"}},{"package":{"name":"products-cmfplone","ecosystem":"PyPI","purl":"pkg:pypi/products-cmfplone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.7"}]}],"versions":["4.0b1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-p7h9-vf92-5fj5/GHSA-p7h9-vf92-5fj5.json"}},{"package":{"name":"products-cmfplone","ecosystem":"PyPI","purl":"pkg:pypi/products-cmfplone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1a1"},{"fixed":"4.1rc3"}]}],"versions":["4.1a1","4.1a2","4.1a3","4.1b1","4.1b2","4.1rc2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-p7h9-vf92-5fj5/GHSA-p7h9-vf92-5fj5.json","last_known_affected_version_range":"\u003c= 4.1rc2"}},{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1"}]}],"versions":["3.2","3.2.1","3.2.2","3.2.3","3.2a1","3.2rc1","3.3","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.3b1","3.3rc1","3.3rc2","3.3rc3","3.3rc4","3.3rc5","4.0","4.0.1","4.0.10","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","4.0a1","4.0a2","4.0a3","4.0a4","4.0a5","4.0b1","4.0b2","4.0b3","4.0b4","4.0b5","4.0rc1","4.1","4.1a1","4.1a2","4.1a3","4.1b1","4.1b2","4.1rc2","4.1rc3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-p7h9-vf92-5fj5/GHSA-p7h9-vf92-5fj5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}