PT-2014-2758 · Plone Foundation · Plone
Jan Lieskovsky
·
Publicado
2014-03-11
·
Atualizado
2022-05-17
·
CVE-2013-4195
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Plone versions 2.1 through 4.1
Plone versions 4.2.x through 4.2.5
Plone versions 4.3.x through 4.3.1
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This is due to multiple open redirect vulnerabilities in the marmoset patch.py, publish.py, and principiaredirect.py scripts.
Recommendations
For Plone versions 2.1 through 4.1, update to a version outside of this range to resolve the issue.
For Plone versions 4.2.x through 4.2.5, update to a version outside of this range to resolve the issue.
For Plone versions 4.3.x through 4.3.1, update to a version outside of this range to resolve the issue.
Correção
RCE
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Plone