Executive brief
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
Affected products
- PyPI products-cmfplone
- PyPI plone
Junglewise Threat Intelligence
CVE-2013-7061 · Severity: low · CVSS 3.1 · Published 2014-05-02
Technologies: products-cmfplone (PyPI), plone (PyPI). Vendors: PyPI.
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.