PT-2014-2758 · Plone Foundation · Plone
Jan Lieskovsky
·
Published
2014-03-11
·
Updated
2022-05-17
·
CVE-2013-4195
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Plone versions 2.1 through 4.1
Plone versions 4.2.x through 4.2.5
Plone versions 4.3.x through 4.3.1
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This is due to multiple open redirect vulnerabilities in the marmoset patch.py, publish.py, and principiaredirect.py scripts.
Recommendations
For Plone versions 2.1 through 4.1, update to a version outside of this range to resolve the issue.
For Plone versions 4.2.x through 4.2.5, update to a version outside of this range to resolve the issue.
For Plone versions 4.3.x through 4.3.1, update to a version outside of this range to resolve the issue.
Fix
RCE
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plone