Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
plone isurlinportal vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-32806
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal before 1.2.0 have an Open Redirect vulnerability. Various parts of Plone use the 'is url in portal' check for security, mostly to see if it is safe to redirect ...
Plone Isurlinportal
NA
CVE-2013-4200
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 treats URLs starting with a space as a relative URL, which allows remote malicious users to bypass the allow_ex...
Plone Plone 3.3
Plone Plone 4.0.5
Plone Plone 3.0.1
Plone Plone 3.0
Plone Plone 3.2.3
Plone Plone 3.1.4
Plone Plone 3.1.5.1
Plone Plone 2.1.4
Plone Plone 4.0.2
Plone Plone 3.3.5
Plone Plone 3.0.6
Plone Plone 3.2
Plone Plone 3.1.1
Plone Plone 2.1.1
Plone Plone 3.3.4
Plone Plone 3.3.2
Plone Plone 4.0.4
Plone Plone 3.1.7
Plone Plone 4.1
Plone Plone 3.2.2
Plone Plone 2.1.2
Plone Plone 3.0.3
1 EDB exploit
6.1
CVSSv3
CVE-2017-1000481
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse this by letting you...
Plone Plone 5.0
Plone Plone 5.1
Plone Plone 5.0.9
Plone Plone 5.0.8
Plone Plone 5.0.7
Plone Plone 4.3.8
Plone Plone 4.3.7
Plone Plone 4.3.6
Plone Plone 4.3.5
Plone Plone 4.1.6
Plone Plone 4.1.5
Plone Plone 4.1.4
Plone Plone 4.1.3
Plone Plone 4.0
Plone Plone 3.3.6
Plone Plone 3.3.5
Plone Plone 3.3.4
Plone Plone 3.3.3
Plone Plone 5.0.1
Plone Plone 4.3.15
Plone Plone 4.3.14
Plone Plone 4.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started