7 vulnerabilities in the Plone content management system

For the open content management system Plone, written in Python using the Zope application server, has been published patches addressing 7 vulnerabilities (CVE identifiers not yet assigned). The issues affect all current releases of Plone, including the release that was created a few days ago 5.2.1. The problems are scheduled to be fixed in upcoming Plone releases 4.3.20, 5.1.7, and 5.2.2, before which it is recommended to use hotfix.

Identified vulnerabilities (details are not yet disclosed):

  • Privilege escalation through manipulation of the Rest API (only occurs with plone.restapi enabled);
  • SQL code injection due to insufficient SQL escaping in DTML and database connection objects (the issue is specific to Zope and manifests in other applications based on it);
  • Content overwrite through manipulations with the PUT method without write permissions;
  • Open redirect in the login form;
  • Potential to pass malicious external links bypassing isURLInPortal checks;
  • Failure of password strength checks in certain cases;
  • Cross-site scripting (XSS) via code injection in a header field.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster