CVE-2012-5502

low
Published 2014-09-30 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2
3.5
VIR risk
3.5

Description

Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://plone.org/products/plone/security/advisories/20121106/18

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://plone.org/products/plone-hotfix/releases/20121106

Package impact

EcosystemPackageVulnerableFixed
python PyPIplone<4.2.34.2.3
python PyPIplone>=4.3a0,<4.3b14.3b1

Application impact

VendorProductVersionsFixed
ploneplone{"endIncluding":"4.2.2"}
ploneplone1.0
ploneplone1.0.1
ploneplone1.0.2
ploneplone1.0.3
ploneplone1.0.4
ploneplone1.0.5
ploneplone1.0.6
ploneplone2.0
ploneplone2.0.1
ploneplone2.0.2
ploneplone2.0.3
ploneplone2.0.4
ploneplone2.0.5
ploneplone2.1
ploneplone2.1.1
ploneplone2.1.2
ploneplone2.1.3
ploneplone2.1.4
ploneplone2.5
ploneplone2.5.1
ploneplone2.5.2
ploneplone2.5.3
ploneplone2.5.4
ploneplone2.5.5
ploneplone3.0
ploneplone3.0.1
ploneplone3.0.2
ploneplone3.0.3
ploneplone3.0.4
ploneplone3.0.5
ploneplone3.0.6
ploneplone3.1
ploneplone3.1.1
ploneplone3.1.2
ploneplone3.1.3
ploneplone3.1.4
ploneplone3.1.5.1
ploneplone3.1.6
ploneplone3.1.7
ploneplone3.2
ploneplone3.2.1
ploneplone3.2.2
ploneplone3.2.3
ploneplone3.3
ploneplone3.3.1
ploneplone3.3.2
ploneplone3.3.3
ploneplone3.3.4
ploneplone3.3.5
ploneplone4.0
ploneplone4.0.1
ploneplone4.0.2
ploneplone4.0.3
ploneplone4.0.4
ploneplone4.0.5
ploneplone4.0.6.1
ploneplone4.1
ploneplone4.1.4
ploneplone4.1.5
ploneplone4.1.6
ploneplone4.2
ploneplone4.2.0.1
ploneplone4.2.1
ploneplone4.2.1.1
ploneplone4.3

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.