<em style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-1948" target="_blank">CVE</a>)</em> : Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Plone has released patch 20110531 to address this vulnerability. Check the vendor advisory or solution in the references section.