Plone 'typeswidget.py' CVE-2013-4193 Security Bypass Vulnerability
BID:61962
Info
Plone 'typeswidget.py' CVE-2013-4193 Security Bypass Vulnerability
| Bugtraq ID: | 61962 |
| Class: | Design Error |
| CVE: |
CVE-2013-4193 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2013 12:00AM |
| Updated: | Mar 19 2015 09:05AM |
| Credit: | Matthew Wilkes |
| Vulnerable: |
Plone Plone 4.1.3 Plone Plone 4.0.8 Plone Plone 4.0.7 Plone Plone 3.3.5 Plone Plone 3.3.4 Plone Plone 3.3.3 Plone Plone 3.3.2 Plone Plone 3.3.1 Plone Plone 3.2.3 Plone Plone 3.2.2 Plone Plone 3.1.6 Plone Plone 3.1.4 Plone Plone 3.0.5 Plone Plone 3.0.4 Plone Plone 3.0.3 Plone Plone 3.0.2 Plone Plone 3.0.1 Plone Plone 2.5.5 Plone Plone 2.5.4 Plone Plone 2.5.1 Plone Plone 2.1.2 Plone Plone 2.0.5 Plone Plone 2.0.4 Plone Plone 4.2a2 Plone Plone 4.2a1 Plone Plone 4.2 Plone Plone 4.1 Plone Plone 4.0.9 Plone Plone 4.0.6.1 Plone Plone 4.0.5 Plone Plone 4.0.4 Plone Plone 4.0.3 Plone Plone 4.0.2 Plone Plone 4.0.1 Plone Plone 4.0 Plone Plone 3.3.2 Plone Plone 3.3.1 Plone Plone 3.3 Plone Plone 3.3 Plone Plone 3.2.3 Plone Plone 3.2.2 Plone Plone 3.2.1 Plone Plone 3.2 Plone Plone 3.1.7 Plone Plone 3.1.6 Plone Plone 3.1.5.1 Plone Plone 3.1.3 Plone Plone 3.1.2 Plone Plone 3.1.1 Plone Plone 3.1 Plone Plone 3.0.6 Plone Plone 3.0 Plone Plone 2.5 Plone Plone 2.1.3 Plone Plone 2.1.1 Plone Plone 2.1 Plone Plone 2.0.2 Plone Plone 2.0.1 Plone Plone 1.0.6 Plone Plone 1.0.5 Plone Plone 1.0.4 Plone Plone 1.0.3 Plone Plone 1.0.2 Plone Plone 1.0.1 |
| Not Vulnerable: | |
Discussion
Plone 'typeswidget.py' CVE-2013-4193 Security Bypass Vulnerability
Plone is prone to a security-bypass vulnerability.
Successful exploits will allow attackers to bypass authentication and perform unauthorized actions, which may aid in further attacks.
Note: This issue was previously discussed in the BID 61544 (Plone Multiple Remote Security Vulnerabilities) but has been moved to its own record to better document it.
Plone is prone to a security-bypass vulnerability.
Successful exploits will allow attackers to bypass authentication and perform unauthorized actions, which may aid in further attacks.
Note: This issue was previously discussed in the BID 61544 (Plone Multiple Remote Security Vulnerabilities) but has been moved to its own record to better document it.
Exploit / POC
Plone 'typeswidget.py' CVE-2013-4193 Security Bypass Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Plone 'typeswidget.py' CVE-2013-4193 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Plone 'typeswidget.py' CVE-2013-4193 Security Bypass Vulnerability
References:
References:
- Plone Homepage (Plone)