CVE-2021-33507
MEDIUMCVSS 6.1/10EPSS 0.77%
Last modified
CVE-2021-33507 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Plone | Plone | <= 4.3.20 |
| Plone | Plone | >= 5.0, <= 5.2.4 |
| Zope | Zope | < 2.5.1 |
References
- http://www.openwall.com/lists/oss-security/2021/05/22/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/05/22/1Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33507?
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
How severe is CVE-2021-33507?
CVE-2021-33507 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.77% probability of exploitation in the next 30 days.
How do I fix CVE-2021-33507?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33501Overwolf Client 0.169.0.22 allows XSS, with resultant Remote…9.6
- CVE-2021-33502The normalize-url package before 4.5.1, 5.x before 5.3.1, an…7.5
- CVE-2021-33503An issue was discovered in urllib3 before 1.26.5. When provi…7.5
- CVE-2021-33504Couchbase Server before 7.1.0 has Incorrect Access Control.4.9
- CVE-2021-33505A local malicious user can circumvent the Falco detection en…7.8
- CVE-2021-33506jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not …7.5
- CVE-2021-33508Plone through 5.2.4 allows XSS via a full name that is misha…5.4
- CVE-2021-33509Plone through 5.2.4 allows remote authenticated managers to …9.9
- CVE-2021-3351OpenPLC runtime V3 through 2016-03-14 allows stored XSS via …5.4
- CVE-2021-33510Plone through 5.2.4 allows remote authenticated managers to …4.3
- CVE-2021-33511Plone though 5.2.4 allows SSRF via the lxml parser. This aff…7.5
- CVE-2021-33512Plone through 5.2.4 allows stored XSS attacks (by a Contribu…5.4
Are you affected by CVE-2021-33507?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
