Plone

Plone

103 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.01%
  • Veröffentlicht 17.12.2020 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:26:55

The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achi...

  • EPSS 0.34%
  • Veröffentlicht 23.01.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:02

An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.

  • EPSS 0.5%
  • Veröffentlicht 23.01.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:02

An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.

  • EPSS 0.63%
  • Veröffentlicht 23.01.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:02

plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.

  • EPSS 0.51%
  • Veröffentlicht 23.01.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:03

SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)

  • EPSS 0.34%
  • Veröffentlicht 23.01.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:03

Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.

  • EPSS 0.62%
  • Veröffentlicht 23.01.2020 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:03

A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.

  • EPSS 0.76%
  • Veröffentlicht 02.01.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 02:00:15

Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2, allow remote attackers to inject arbitrary web script or HTML via...

  • EPSS 0.2%
  • Veröffentlicht 03.01.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:50

By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination with another ...

  • EPSS 0.2%
  • Veröffentlicht 03.01.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:49

When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse...