CVE-2013-7061
Plone 3.3-4.3.2 - Authenticated Information Disclosure via Search API
Title source: llmDescription
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://plone.org/security/20131210/catalogue-exposure
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/12/12/3
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/12/10/15
Scores
EPSS
0.0095
EPSS Percentile
57.6%
Details
CWE
CWE-264
Status
published
Products (35)
plone/plone
3.3
plone/plone
3.3.1
plone/plone
3.3.2
plone/plone
3.3.3
plone/plone
3.3.4
plone/plone
3.3.5
plone/plone
3.3.6
plone/plone
4.0
plone/plone
4.0.1
plone/plone
4.0.2
... and 25 more
Published
May 02, 2014
Tracked Since
Feb 18, 2026