NA

CVE-2024-22889

Published: 06/03/2024 Updated: 06/03/2024

Vulnerability Summary

Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.

Github Repositories

Product: Plone CMS Version: v609 Date found: 10012024 Date reported: 10012024 Vulnerability type: Incorrect Access Control CVE ID: CVE-2024-22889 Description: Due to incorect access control in Plone version v609, remote attackers can view and list all files hosted on the website via sending a crafted request POC is coming soon:)