GHSA-6fgf-x7wg-hp8r
Dashboard / Vulnerabilities / GHSA-6fgf-x7wg-hp8r
GHSA-6fgf-x7wg-hp8r
Summary: Plone Unrestricted Filed Manipulation vulnerability via content edit forms
Details: typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.
References: https://nvd.nist.gov/vuln/detail/CVE-2013-4193, https://bugzilla.redhat.com/show_bug.cgi?id=978469, https://github.com/plone/Plone, https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2014-57.yaml, http://plone.org/products/plone-hotfix/releases/20130618, http://plone.org/products/plone/security/advisories/20130618-announcement, http://seclists.org/oss-sec/2013/q3/261
Affected packages
Package
Name: plone
Purl: pkg:pypi/plone
Affected ranges
Type: ECOSYSTEM
Events:
