Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alan Hoey

Pesquisador dePlone security team
#19271de 53,633
13.8CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2014-2320
8.5
2014-09-30
Plone Foundation · Plone · CVE-2012-5493
**Name of the Vulnerable Software and Affected Versions** Plone versions prior to 4.2.3 Plone versions 4.3 before beta 1 **Description** The issue allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors. This is related to the `gtbn.py` module. **Recommendations** For Plone versions prior to 4.2.3, update to version 4.2.3 or later. For Plone versions 4.3 before beta 1, update to beta 1 or later. As a temporary workaround, consider restricting access to the `gtbn.py` module to minimize the risk of exploitation.
PT-2014-2331
5.3
2014-09-30
Plone Foundation · Plone · CVE-2012-5504
**Name of the Vulnerable Software and Affected Versions** Plone versions prior to 4.2.3 Plone versions 4.3 prior to beta 1 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. **Recommendations** For versions prior to 4.2.3, update to version 4.2.3 or later. For versions 4.3 prior to beta 1, update to beta 1 or later.