CVE-2021-33926

HIGH

Plone 4.3.2-5.2.4 - Server-Side Request Forgery via RSS Feed Portlet

Title source: llm
STIX 2.1

Description

An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.

Scores

CVSS v3 8.8
EPSS 0.0100
EPSS Percentile 58.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-918
Status published
Products (47)
plone/plone 4.3
plone/plone 4.3.1
plone/plone 4.3.2
plone/plone 4.3.3
plone/plone 4.3.4
plone/plone 4.3.5
plone/plone 4.3.6
plone/plone 4.3.7
plone/plone 4.3.8
plone/plone 4.3.9
... and 37 more
Published Feb 17, 2023
Tracked Since Feb 18, 2026