Information Exposure Affecting plone package, versions [,4.2.3) [4.3a1,4.3b1)
Threat Intelligence
EPSS
0.36% (73rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-PLONE-40120
- published 6 Nov 2012
- disclosed 6 Nov 2012
- credit Unknown
Introduced: 6 Nov 2012
CVE-2012-5491 Open this link in a new tabOverview
plone
is a Content Management System.
z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.
References
CVSS Scores
version 3.1