MEDIUM 4.9 PyPI

Plone Privilege escalation through exposed underlying API

GHSA-4vr8-r7qr-fpvq · CVE-2013-7061 · PYSEC-2014-66 · PYSEC-2014-68

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.

Ready to move

Start Securing

Free, no credit card | First findings in minutes