GHSA-f8pg-wp5j-rjxx
Dashboard / Vulnerabilities / GHSA-f8pg-wp5j-rjxx
GHSA-f8pg-wp5j-rjxx
Summary: Plone Information Disclosure
Details: `z3c.form`, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.
References: https://nvd.nist.gov/vuln/detail/CVE-2012-5491, https://github.com/plone/Plone, https://github.com/plone/Products.CMFPlone/blob/4.2.3/docs/CHANGES.txt, https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2014-33.yaml, https://plone.org/products/plone-hotfix/releases/20121106, https://plone.org/products/plone/security/advisories/20121106/07, http://www.openwall.com/lists/oss-security/2012/11/10/1
Affected packages
Package
Name: plone
Purl: pkg:pypi/plone
Affected ranges
Type: ECOSYSTEM
Events:
