CVE-2013-4193
Description
typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.
Risk Information
Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.309
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities are fixed in Python-plone 4.1.1 | Windows |
| Multiple vulnerabilities are fixed in Python-plone 4.2.6 | Windows |
| Multiple vulnerabilities are fixed in Python-plone 4.3.2 | Windows |
| Multiple vulnerabilities are affected in Python-plone 4.1 | Windows |
| Multiple vulnerabilities are fixed in Python-plone for linux 4.1.1 | Linux |
| Multiple vulnerabilities are fixed in Python-plone for linux 4.2.6 | Linux |
| Multiple vulnerabilities are fixed in Python-plone for linux 4.3.2 | Linux |
| Multiple vulnerabilities are affected in Python-plone for linux 4.1 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234