Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alan Hoey

Researcher fromPlone security team
#19278of 53,632
13.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2014-2320
8.5
2014-09-30
Plone Foundation · Plone · CVE-2012-5493
**Name of the Vulnerable Software and Affected Versions** Plone versions prior to 4.2.3 Plone versions 4.3 before beta 1 **Description** The issue allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors. This is related to the `gtbn.py` module. **Recommendations** For Plone versions prior to 4.2.3, update to version 4.2.3 or later. For Plone versions 4.3 before beta 1, update to beta 1 or later. As a temporary workaround, consider restricting access to the `gtbn.py` module to minimize the risk of exploitation.
PT-2014-2331
5.3
2014-09-30
Plone Foundation · Plone · CVE-2012-5504
**Name of the Vulnerable Software and Affected Versions** Plone versions prior to 4.2.3 Plone versions 4.3 prior to beta 1 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. **Recommendations** For versions prior to 4.2.3, update to version 4.2.3 or later. For versions 4.3 prior to beta 1, update to beta 1 or later.