CVE-2012-5492: Infoleak
uidcatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.
Other sources
uidcatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5492?
CVE-2012-5492 has a medium severity rating, indicating it can pose a moderate risk to affected systems.
How do I fix CVE-2012-5492?
To mitigate CVE-2012-5492, it is recommended to upgrade Plone to version 4.2.3 or later, or to apply relevant patches.
What versions are affected by CVE-2012-5492?
CVE-2012-5492 affects Plone versions prior to 4.2.3 and versions of 4.3 before beta 1.
What type of attacks does CVE-2012-5492 expose systems to?
CVE-2012-5492 allows remote attackers to obtain metadata about hidden objects through crafted URLs.
Is there an exploit available for CVE-2012-5492?
While no specific exploits have been publicly disclosed for CVE-2012-5492, its vulnerability can potentially be exploited by attackers.