Vulnerabilities
Vulnerable Software
Plone:  >> Plone  >> 4.3.17  Security Vulnerabilities
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
CVSS Score
5.4
EPSS Score
0.003
Published
2018-01-03
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
CVSS Score
6.0
EPSS Score
0.005
Published
2009-04-23


Contact Us

Shodan ® - All rights reserved