Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login_sites filtering property, redirect users to arbitrary web sites, and conduct phishing attacks via a space before a URL in the "next" parameter to acl_users/credentials_cookie_auth/require_login.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Plone 权限许可和访问控制问题漏洞
Vulnerability Description
Plone是一套基于Zope应用服务器构建的开源内容管理系统(CMS)。 Plone存在权限许可和访问控制问题漏洞。远程攻击者可利用该漏洞绕过allow_external_login_sites过滤属性,重定向用户到任意网站,进而实施钓鱼攻击。以下版本受到影响:Plone 2.1至4.1版本,4.2.x 至4.2.5版本,以及4.3.x至4.3.1版本。
CVSS Information
N/A
Vulnerability Type
N/A