Junglewise Threat Intelligence
CVE-2013-7060: PYSEC-2014-65 - Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a
CVE-2013-7060 · Severity: low · CVSS 3.1 · Published 2014-05-02
Technologies: products-cmfplone (PyPI), plone (PyPI). Vendors: PyPI.
Executive brief
Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.
Affected products
- PyPI products-cmfplone
- PyPI plone