Safety vulnerability ID: 35491
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone 4.3.3 includes a fix for CVE-2013-7061: Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
Latest version: 6.1.1
The Plone Content Management System
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
MLIST:[oss-security] 20131210 CVE request for Plone: http://www.openwall.com/lists/oss-security/2013/12/10/15
MLIST:[oss-security] 20131211 Re: CVE request for Plone: http://www.openwall.com/lists/oss-security/2013/12/12/3
CONFIRM:https://plone.org/security/20131210/catalogue-exposure: https://plone.org/security/20131210/catalogue-exposure
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application