Open Redirect Affecting products.cmfformcontroller package, versions [,3.1.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (72nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-PRODUCTSCMFFORMCONTROLLER-40418
  • published18 Jul 2016
  • disclosed18 Jul 2016
  • creditSebastian Perez

Introduced: 18 Jul 2016

CVE-2016-7137  (opens in a new tab)
CWE-601  (opens in a new tab)

Overview

products.cmfformcontroller is a CMFFormController provides a form validation mechanism for CMF.

Affected versions of this project are vulnerable to Open Redirection. Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.

CVSS Base Scores

version 3.1