Vulnerabilities
Vulnerable Software
Plone:  >> Isurlinportal  >> 4.0.0  Security Vulnerabilities
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0.
CVSS Score
5.3
EPSS Score
0.0
Published
2026-03-05


Contact Us

Shodan ® - All rights reserved