Description

An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory4.0 to < 4.3.20 · Fixed in 4.3.20affected
5.0rc1 to < 5.1.7 · Fixed in 5.1.7affected
5.2.0 to < 5.2.2 · Fixed in 5.2.2affected

References

7