CVE-2013-7060: Infoleak
Published May 2, 2014
·Updated
Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.
Affected Software
35 affected componentsFixes available
pip/Products.CMFPlone>=3.3<4.3.3
4.3.3
pip/plone>=3.3<=4.3.2
4.3.3
Plone plone=3.3
Plone plone=3.3.1
Plone plone=3.3.2
Plone plone=3.3.3
Plone plone=3.3.4
Plone plone=3.3.5
Plone plone=3.3.6
Plone plone=4.0
Plone plone=4.0.1
Plone plone=4.0.2
Plone plone=4.0.3
Plone plone=4.0.4
Plone plone=4.0.5
Plone plone=4.0.7
Plone plone=4.0.9
Plone plone=4.1
Plone plone=4.1.1
Plone plone=4.1.2
Plone plone=4.1.3
Plone plone=4.1.4
Plone plone=4.1.5
Plone plone=4.1.6
Plone plone=4.2
Plone plone=4.2.1
Plone plone=4.2.2
Plone plone=4.2.3
Plone plone=4.2.4
Plone plone=4.2.5
Plone plone=4.2.6
Plone plone=4.2.7
Plone plone=4.3
Plone plone=4.3.1
Plone plone=4.3.2
Event History
May 2, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
04:41 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-7060?
CVE-2013-7060 has a medium severity rating, indicating a moderate risk to affected systems.
2
How do I fix CVE-2013-7060?
To fix CVE-2013-7060, users should upgrade to Plone version 4.3.3 or later.
3
What versions are affected by CVE-2013-7060?
CVE-2013-7060 affects Plone versions from 3.3 to 4.3.2.
4
Can CVE-2013-7060 lead to unauthorized access?
Yes, CVE-2013-7060 can allow remote attackers to gain information about the installation path, potentially leading to further exploitation.
5
Is CVE-2013-7060 a local or remote vulnerability?
CVE-2013-7060 is a remote vulnerability that can be exploited by attackers without needing local access.