For the open content management system , written in Python using the Zope application server, patches addressing (CVE identifiers not yet assigned). The issues affect all current releases of Plone, including the release that was created a few days ago . The problems are scheduled to be fixed in upcoming Plone releases 4.3.20, 5.1.7, and 5.2.2, before which it is recommended to use .
Identified vulnerabilities (details are not yet disclosed):
- Privilege escalation through manipulation of the Rest API (only occurs with plone.restapi enabled);
- SQL code injection due to insufficient SQL escaping in DTML and database connection objects (the issue is specific to and manifests in other applications based on it);
- Content overwrite through manipulations with the PUT method without write permissions;
- Open redirect in the login form;
- Potential to pass malicious external links bypassing isURLInPortal checks;
- Failure of password strength checks in certain cases;
- Cross-site scripting (XSS) via code injection in a header field.
Source: opennet.ru
