Red Hat Bugzilla – Bug 1532485
CVE-2017-1000482 plone: XSS in member's home_page property
Last modified: 2018-01-09 00:24:34 EST
A member of the Plone site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page. References: https://nvd.nist.gov/vuln/detail/CVE-2017-1000482 https://plone.org/security/hotfix/20171128/xss-using-the-home_page-member-property