collective.contact.widget is vulnerable to cross-site scripting
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Dec 22, 2022 
          to the GitHub Advisory Database
          •
          Updated Sep 13, 2024 
      
  
Description
        Published by the National Vulnerability Database
      Dec 21, 2022 
    
  
        Published to the GitHub Advisory Database
      Dec 22, 2022 
    
  
        Reviewed
      Dec 29, 2022 
    
  
        Last updated
      Sep 13, 2024 
    
  
collective.contact.widget is an add-on is part of the collective.contact.* suite. A vulnerability classified as problematic was found in collective.contact.widget up to 1.12. This vulnerability affects the function title of the file src/collective/contact/widget/widgets.py. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 5da36305ca7ed433782be8901c47387406fcda12. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216496.
References