Safety vulnerability ID: 35447
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone 4.1, 4.2.5 and 4.3.1 include a fix for CVE-2013-4195: Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Latest version: 6.1.1
The Plone Content Management System
Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
MLIST:[oss-security] 20130801 Re: CVE Request -- Plone: 20130618 Hotfix (multiple vectors): http://seclists.org/oss-sec/2013/q3/261
CONFIRM:http://plone.org/products/plone-hotfix/releases/20130618: http://plone.org/products/plone-hotfix/releases/20130618
CONFIRM:http://plone.org/products/plone/security/advisories/20130618-announcement: http://plone.org/products/plone/security/advisories/20130618-announcement
CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=978471: https://bugzilla.redhat.com/show_bug.cgi?id=978471
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application