Executive brief
queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.
Affected products
- PyPI plone
Junglewise Threat Intelligence
CVE-2012-5498 · Severity: low · CVSS 3.1 · Published 2014-09-30
Technologies: plone (PyPI). Vendors: PyPI.
queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.