Количество 2
Количество 2
CVE-2026-28413
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0.
GHSA-43gx-6gv6-3jcp
Products.isurlinportal has possible open redirect when using more than 2 forward slashes
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-28413 Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0. | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
GHSA-43gx-6gv6-3jcp Products.isurlinportal has possible open redirect when using more than 2 forward slashes | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу