CVE-2013-4193

Plone 2.1-4.1, 4.2.x-4.2.5, 4.3.x-4.3.1 - Unauthenticated Field Hiding via Crafted URL

Title source: llm
STIX 2.1

Description

typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q3/261
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=978469

Scores

EPSS 0.0119
EPSS Percentile 64.7%

Details

CWE
CWE-264
Status published
Products (50)
plone/plone 2.1
plone/plone 2.1.1
plone/plone 2.1.2
plone/plone 2.1.3
plone/plone 2.1.4
plone/plone 2.5
plone/plone 2.5.1
plone/plone 2.5.2
plone/plone 2.5.3
plone/plone 2.5.4
... and 40 more
Published Mar 11, 2014
Tracked Since Feb 18, 2026