Plone 4.3.x < 5.2.5 Multiple Vulnerabilities (HF 20210518)

critical Nessus Plugin ID 329024

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Plone installed on the remote host is 4.3.x prior to 5.2.5. It is, therefore, affected by the following vulnerabilities:

- Plone CMS has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. (CVE-2021-3313)

- Products.PluggableAuthService within Zope has an information disclosure vulnerability - everyone can list the names of roles defined in the ZODB Role Manager plugin if the site uses this plugin. (CVE-2021-21336)

- Products.GenericSetup within Zope has an information disclosure vulnerability - anonymous visitors may view log and snapshot files generated by the Generic Setup Tool. (CVE-2021-21360)

- Zope has a remote code execution vulnerability via a traversal in the TAL expressions. (CVE-2021-32633, CVE-2021-32674)

- The AccessControl module within Zope has a remote code execution via the use of unsafe classes in permitted modules. (CVE-2021-32807)

- Zope Products.CMFCore and Products.PluggableAuthService, as used in Plone and other products, allow Reflected XSS. (CVE-2021-33507)

- Plone allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item. (CVE-2021-33508)

- Plone allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script. (CVE-2021-33509)

- Plone allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file. (CVE-2021-33510)

- Plone allows SSRF via the lxml parser. (CVE-2021-33511)

- Plone allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document. (CVE-2021-33512)

- Plone allows XSS via the inline_diff methods in Products.CMFDiffTool. (CVE-2021-33513)

- An issue in Plone CMS allows an attacker to access sensitive information via the RSS feed portlet.
(CVE-2021-33926)

- In Plone, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field (CVE-2021-35959)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number. Since a vendor hotfix (PloneHotfix20210518) may remediate this without a version upgrade, this plugin only reports when running in Paranoid mode.

Solution

Apply the vendor hotfix (Products.PloneHotfix20210518), or upgrade to Plone 5.2.5 or later.

See Also

https://plone.org/security/hotfix/20210518/

http://www.openwall.com/lists/oss-security/2021/05/22/1

Plugin Details

Severity: Critical

ID: 329024

File Name: plone_HF_20210518.nasl

Version: 1.2

Type: Local

Family: Misc.

Published: 7/22/2026

Updated: 7/23/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 95.09

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2021-33509

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Temporal Score: 8.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:plone:plone

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/18/2021

Vulnerability Publication Date: 5/27/2020

Reference Information

CVE: CVE-2021-21336, CVE-2021-21360, CVE-2021-32633, CVE-2021-32674, CVE-2021-32807, CVE-2021-3313, CVE-2021-33507, CVE-2021-33508, CVE-2021-33509, CVE-2021-33510, CVE-2021-33511, CVE-2021-33512, CVE-2021-33513, CVE-2021-33926, CVE-2021-35959