PT-2018-5246 · Plone Foundation · Plone

Publicado

2018-01-03

·

Atualizado

2022-05-14

·

CVE-2017-1000481

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Plone versions 2.5 through 5.1rc1
Description The issue allows an attacker to potentially trick users into accessing malicious sites or executing attacker-controlled JavaScript after logging in, by exploiting the redirect mechanism that uses the came from parameter. Although Plone has measures like the isURLInPortal check to restrict redirects to within the same Plone site, additional methods to bypass these checks were found and addressed.
Recommendations For Plone versions 2.5 through 5.1rc1, apply the provided hotfix to prevent the exploitation of the redirect mechanism.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000481
GHSA-8G72-GQ68-6GQH
PYSEC-2018-70

Produtos afetados

Plone