CVE-2013-4193
- EPSS 0.31%
- Veröffentlicht 11.03.2014 19:37:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.
CVE-2013-4194
- EPSS 0.32%
- Veröffentlicht 11.03.2014 19:37:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers to obtain sensitive information via a crafted URL, which reveals the installation path in an error message.
CVE-2013-4195
- EPSS 0.29%
- Veröffentlicht 11.03.2014 19:37:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and c...
- EPSS 0.32%
- Veröffentlicht 11.03.2014 19:37:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a cra...
CVE-2013-4197
- EPSS 0.5%
- Veröffentlicht 11.03.2014 19:37:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.
- EPSS 0.31%
- Veröffentlicht 11.03.2014 19:37:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.
CVE-2013-4199
- EPSS 0.48%
- Veröffentlicht 11.03.2014 19:37:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompre...
CVE-2013-4200
- EPSS 5.3%
- Veröffentlicht 21.01.2014 16:06:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login...
- EPSS 0.93%
- Veröffentlicht 30.12.2011 01:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
CVE-2011-3587
- EPSS 90.46%
- Veröffentlicht 10.10.2011 10:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python mod...