CVE-2013-7061: Medium severity Plone plone vulnerability
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
Other sources
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7061?
CVE-2013-7061 is classified as having a medium severity due to its potential for unauthorized information exposure.
How do I fix CVE-2013-7061?
To fix CVE-2013-7061, upgrade Plone to version 4.3.3 or higher.
Which versions of Plone are affected by CVE-2013-7061?
CVE-2013-7061 affects Plone versions from 3.3 through 4.3.2.
What type of vulnerability is CVE-2013-7061?
CVE-2013-7061 is a vulnerability that allows remote administrators to bypass restrictions and access sensitive information.
Can CVE-2013-7061 be exploited remotely?
Yes, CVE-2013-7061 can be exploited remotely by administrators with access to the vulnerable search API.