CVE-2013-4193
- EPSS 0.31%
- Published 11.03.2014 19:37:02
- Last modified 12.04.2025 10:46:40
typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.
CVE-2013-4194
- EPSS 0.32%
- Published 11.03.2014 19:37:02
- Last modified 12.04.2025 10:46:40
The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers to obtain sensitive information via a crafted URL, which reveals the installation path in an error message.
CVE-2013-4195
- EPSS 0.29%
- Published 11.03.2014 19:37:02
- Last modified 12.04.2025 10:46:40
Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and c...
- EPSS 0.32%
- Published 11.03.2014 19:37:02
- Last modified 12.04.2025 10:46:40
The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a cra...
CVE-2013-4197
- EPSS 0.5%
- Published 11.03.2014 19:37:02
- Last modified 12.04.2025 10:46:40
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.
- EPSS 0.31%
- Published 11.03.2014 19:37:02
- Last modified 12.04.2025 10:46:40
mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.
CVE-2013-4199
- EPSS 0.48%
- Published 11.03.2014 19:37:02
- Last modified 12.04.2025 10:46:40
(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompre...
CVE-2013-4200
- EPSS 5.3%
- Published 21.01.2014 16:06:19
- Last modified 11.04.2025 00:51:21
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login...
- EPSS 0.89%
- Published 30.12.2011 01:55:01
- Last modified 11.04.2025 00:51:21
Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
CVE-2011-3587
- EPSS 90.59%
- Published 10.10.2011 10:55:06
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python mod...