CVE-2011-1949

Publication date 6 June 2011

Last updated 24 July 2024


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.

Status

Package Ubuntu Release Status
zope-cmfplone 11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Ignored end of life