Products.ATContentTypes Reflected Cross-Site Scripting and Open Redirect Vulnerability

Vulnerability

A reflected cross-site scripting and open redirect vulnerability has been identified in Products.ATContentTypes versions prior to 3.0.6, which are used in Plone versions 2.1 to 4.3. The vulnerability arises when an attacker manages to cache a compromised version of the 'image_view_fullscreen' page, for example, using Varnish. This cache poisoning can lead to redirection of subsequent visitors who click on links on the affected page. While this issue typically impacts only anonymous users, it can vary based on individual cache settings.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser. Additionally, the open redirect feature can be misused to redirect users to untrusted sites, potentially leading to phishing or other malicious activities.

Remediation

Users can upgrade to Products.ATContentTypes version 3.0.6, which is compatible with Plone 5.2 (Python 2 only). For versions prior to 3.0.6, ensure that the 'image_view_fullscreen' page is not cached. This can be done by removing it from the 'Content item view' templates in the 'Caching' control panel.

Added: Jun 22, 2026, 11:07 AM
Updated: Jun 22, 2026, 11:07 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
6.8
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.