为 Plone 提供事件(event)内容类型。在 5.2.4 和 6.0.1 版本之前, 中的 iCalendar 导入功能存在以下安全缺陷: 1. 对日历 URL 和事件 URL 的访问限制不足; 2. 未对下载的字节数或导入的事件数量进行充分限制; 3. 按单个事件提交事务(commit),缺乏事务保护。 因此,已登录的编辑用户(editor)可以: 使服务器请求内部网络资源或本地日历文件(可能导致服务端请求伪造 SSRF 或本地文件读取); 耗尽服务器资源,导致站点不可用; 存储一个恶意的事件 URL,当其
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| plone | plone.app.event | < 5.2.4 |
affected |
>= 6.0.0, < 6.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| plone | plone.app.event | < 5.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet