Junglewise Threat Intelligence

CVE-2013-7061: PYSEC-2014-68 - Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive informa

CVE-2013-7061 · Severity: low · CVSS 3.1 · Published 2014-05-02

Technologies: products-cmfplone (PyPI), plone (PyPI). Vendors: PyPI.

Executive brief

Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.

Affected products

  • PyPI products-cmfplone
  • PyPI plone

Related threats