Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
plone isurlinportal vulnerabilities and exploits
(subscribe to this query)
5.8
CVSSv2
CVE-2021-32806
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal before 1.2.0 have an Open Redirect vulnerability. Various parts of Plone use the 'is url in portal' check for security, mostly to see if it is safe to redirect ...
Plone Isurlinportal
5.8
CVSSv2
CVE-2017-1000481
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse this by letting you...
Plone Plone 3.3
Plone Plone 4.3.3
Plone Plone 4.3.11
Plone Plone 4.0.5
Plone Plone 4.3.6
Plone Plone 5.0.1
Plone Plone 4.2.3
Plone Plone 5.0.2
Plone Plone 5.0
Plone Plone 4.0.2
Plone Plone 5.0.5
Plone Plone 3.3.5
Plone Plone 4.3.5
Plone Plone 4.3.10
Plone Plone 5.0.3
Plone Plone 4.3
Plone Plone 4.2.2
Plone Plone 4.0.8
Plone Plone 5.0.6
Plone Plone 3.3.4
Plone Plone 4.0.7
Plone Plone 3.3.2
5.8
CVSSv2
CVE-2013-4200
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 treats URLs starting with a space as a relative URL, which allows remote malicious users to bypass the allow_ex...
Plone Plone 3.3
Plone Plone 4.0.5
Plone Plone 3.0.1
Plone Plone 3.0
Plone Plone 3.2.3
Plone Plone 3.1.4
Plone Plone 3.1.5.1
Plone Plone 2.1.4
Plone Plone 4.0.2
Plone Plone 3.3.5
Plone Plone 3.0.6
Plone Plone 3.2
Plone Plone 3.1.1
Plone Plone 2.1.1
Plone Plone 3.3.4
Plone Plone 3.3.2
Plone Plone 4.0.4
Plone Plone 3.1.7
Plone Plone 4.1
Plone Plone 3.2.2
Plone Plone 2.1.2
Plone Plone 3.0.3
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27802
template injection
CVE-2024-0044
code injection
CVE-2024-35474
CVE-2024-27857
CVE-2024-23251
CVE-2024-23692
physical
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started