It was found that Plone's URL checking infrastructure includes a method for checking if URLs valid and located in the Plone site. By passing javascript into this specially crafted url, XSS can be achieved. CVE assignment: http://seclists.org/oss-sec/2016/q3/417 External References: https://plone.org/security/hotfix/20160830/non-persistent-xss-in-plone-1
Created plone tracking bugs for this issue: Affects: epel-5 [bug 1373467]