logo

CVE-2013-7060 products.cmfplone

Package

Manager: pip
Name: products.cmfplone
Vulnerable Version: >=3.3 <4.3.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00283 pctl0.51246

Details

Plone Filesystem path information leak Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.

Metadata

Created: 2022-05-17T04:41:01Z
Modified: 2024-10-15T17:36:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rg52-j87w-pf83/GHSA-rg52-j87w-pf83.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-rg52-j87w-pf83
Finding: F038
Auto approve: 1