—
PYSEC-2010-19
Quick fix
PYSEC-2010-19 — plone: upgrade to the fixed version with the command below.
pip install --upgrade 'plone>=3.3.5'Details
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
Are you affected?
Enter the version of the package you're using.