5.5
CVSSv2

CVE-2013-7061

Published: 02/05/2014 Updated: 30/06/2014
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Products/CMFPlone/CatalogTool.py in Plone 3.3 up to and including 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone 4.1.6

plone plone 3.3

plone plone 4.0.9

plone plone 4.0.7

plone plone 4.1

plone plone 4.1.1

plone plone 4.1.2

plone plone 4.1.3

plone plone 4.0.1

plone plone 4.0

plone plone 3.3.6

plone plone 3.3.5

plone plone 4.2.5

plone plone 4.2.6

plone plone 4.2.7

plone plone 4.3

plone plone 4.1.4

plone plone 4.0.4

plone plone 4.0.2

plone plone 3.3.4

plone plone 3.3.2

plone plone 4.2.1

plone plone 4.2.3

plone plone 4.3.2

plone plone 4.1.5

plone plone 4.0.5

plone plone 4.0.3

plone plone 3.3.3

plone plone 3.3.1

plone plone 4.2

plone plone 4.2.2

plone plone 4.2.4

plone plone 4.3.1

Vendor Advisories

Products/CMFPlone/CatalogToolpy in Plone 33 through 432 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API ...