Cross-site Request Forgery (CSRF) Affecting plone package, versions [,4.3.7) [5.0a1,5.0)
Threat Intelligence
EPSS
0.3% (71st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-PLONE-40343
- published 7 Nov 2017
- disclosed 27 Feb 2016
- credit Unknown
Introduced: 27 Feb 2016
CVE-2015-7293 Open this link in a new tabOverview
plone
is a Content Management System.
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF). Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
References
CVSS Scores
version 3.1