Filtered by vendor Plone
Subscribe
Search
Total
11 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-32633 | 2 Plone, Zope | 2 Plone, Zope | 2021-07-30 | 6.5 MEDIUM | 8.8 HIGH |
| Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for direct use. By default, only users with the Manager role can add or edit Zope Page Templates through the web, but sites that allow untrusted users to add/edit Zope Page Templates through the web are at risk from this vulnerability. The problem has been fixed in Zope 5.2 and 4.6. As a workaround, a site administrator can restrict adding/editing Zope Page Templates through the web using the standard Zope user/role permission mechanisms. Untrusted users should not be assigned the Zope Manager role and adding/editing Zope Page Templates through the web should be restricted to trusted users only. | |||||
| CVE-2020-7938 | 1 Plone | 1 Plone | 2021-07-21 | 6.5 MEDIUM | 8.8 HIGH |
| plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level. | |||||
| CVE-2021-33511 | 1 Plone | 1 Plone | 2021-05-24 | 5.0 MEDIUM | 7.5 HIGH |
| Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel. | |||||
| CVE-2020-28734 | 1 Plone | 1 Plone | 2021-01-04 | 6.5 MEDIUM | 8.8 HIGH |
| Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. | |||||
| CVE-2020-28735 | 1 Plone | 1 Plone | 2021-01-04 | 6.5 MEDIUM | 8.8 HIGH |
| Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). | |||||
| CVE-2020-28736 | 1 Plone | 1 Plone | 2021-01-04 | 6.5 MEDIUM | 8.8 HIGH |
| Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role). | |||||
| CVE-2020-7939 | 1 Plone | 1 Plone | 2020-01-24 | 6.5 MEDIUM | 8.8 HIGH |
| SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.) | |||||
| CVE-2020-7940 | 1 Plone | 1 Plone | 2020-01-24 | 5.0 MEDIUM | 7.5 HIGH |
| Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking. | |||||
| CVE-2015-7293 | 2 Plone, Zope | 2 Plone, Zope Management Interface | 2017-10-06 | 6.8 MEDIUM | 8.8 HIGH |
| Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x. | |||||
| CVE-2015-7318 | 1 Plone | 1 Plone | 2017-10-03 | 5.0 MEDIUM | 7.5 HIGH |
| Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses. | |||||
| CVE-2016-4041 | 1 Plone | 1 Plone | 2017-02-27 | 7.5 HIGH | 7.3 HIGH |
| Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors. | |||||
