Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r82h-mqw3-fc56

Опубликовано: 28 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

plone.app.event vulnerable to denial of service via iCalendar import

Impact

By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.

Patches

The problem has been patched in plone.app.event.

  • For Plone 6.2: upgrade to plone.app.event 6.0.1
  • For Plone 6.1: upgrade to plone.app.event 5.2.4
  • For Plone 6.0: upgrade to plone.app.event 5.2.4

Workarounds

In the site root, go to the Security tab of the Zope Management Interface (manage_access), look for the "plone.app.event: Import Ical" permission, and grant this only to the Manager role. Then only users with the Manager role can use the ical import form.

There is no workaround for the stored XSS in the URL field of events.

The vulnerabilities were discovered by Timothy Dudley and responsibly reported to the Plone Security Team. Thank you!

Пакеты

Наименование

plone.app.event

pip
Затронутые версииВерсия исправления

< 5.2.4

5.2.4

Наименование

plone.app.event

pip
Затронутые версииВерсия исправления

>= 6.0.0a1, < 6.0.1

6.0.1

EPSS

Процентиль: 28%
0.00343
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 9.1
nvd
19 дней назад

plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar files, exhaust resources and take the site offline, and store a malicious event URL that executes script in another user's browser. The fix restricts accepted URLs, applies MAXIMUM_ICAL_IMPORT_SIZE_BYTES and MAXIMUM_ICAL_IMPORT_EVENTS limits, uses transaction savepoints, and validates event URLs. This issue is fixed in versions 5.2.4 and 6.0.1.

EPSS

Процентиль: 28%
0.00343
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-400