Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-69vh-662j-v988

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Plone Open Redirect Vulnerability

Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 5.0, <= 5.0.6

Отсутствует

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.0, <= 4.3.11

Отсутствует

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 3.3, <= 3.3.6

Отсутствует

EPSS

Процентиль: 64%
0.00477
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.7
redhat
больше 9 лет назад

Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.

CVSS3: 6.1
nvd
почти 9 лет назад

Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.

EPSS

Процентиль: 64%
0.00477
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-601