Safety vulnerability ID: 40535
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.
Latest version: 6.1.1
The Plone Content Management System
Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file. See CVE-2021-33510.
MISC:https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-event-ical-url: https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-event-ical-url
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application