CVE-2015-7293: CSRF
Published Sep 25, 2017
·Updated
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
Affected Software
48 affected componentsFixes available
pip/Plone<5.0a1
5.0a1
Plone plone=3.3
Plone plone=3.3.1
Plone plone=3.3.2
Plone plone=3.3.3
Plone plone=3.3.4
Plone plone=3.3.5
Plone plone=3.3.6
Plone plone=4.0
Plone plone=4.0.1
Plone plone=4.0.2
Plone plone=4.0.3
Plone plone=4.0.4
Plone plone=4.0.5
Plone plone=4.0.7
Plone plone=4.0.8
Plone plone=4.0.9
Plone plone=4.0.10
Plone plone=4.1
Plone plone=4.1.1
Plone plone=4.1.2
Plone plone=4.1.3
Plone plone=4.1.4
Plone plone=4.1.5
Plone plone=4.1.6
Plone plone=4.2
Plone plone=4.2.1
Plone plone=4.2.2
Plone plone=4.2.3
Plone plone=4.2.4
Plone plone=4.2.5
Plone plone=4.2.6
Plone plone=4.2.7
Plone plone=4.3
Plone plone=4.3.1
Plone plone=4.3.2
Plone plone=4.3.3
Plone plone=4.3.4
Plone plone=4.3.5
Plone plone=4.3.6
Plone plone=4.3.7
Plone plone=4.3.8
Plone plone=4.3.9
Plone plone=4.3.10
Plone plone=4.3.11
Plone plone=4.3.12
Plone plone=4.3.14
Zope Zope Management Interface<=4.3.7
Event History
Sep 25, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·12:34 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-7293?
CVE-2015-7293 is classified as a high severity vulnerability due to its impact on the security of the Zope Management Interface and Plone.
2
How do I fix CVE-2015-7293?
To fix CVE-2015-7293, upgrade to Plone version 5.0a1 or higher and ensure all relevant security patches are applied.
3
What are the affected versions of Plone for CVE-2015-7293?
CVE-2015-7293 affects multiple versions of Plone including 3.3 through 4.3.7.
4
Is CVE-2015-7293 related to cross-site request forgery (CSRF)?
Yes, CVE-2015-7293 involves multiple cross-site request forgery vulnerabilities.
5
Are there specific versions of Zope Management Interface that are vulnerable to CVE-2015-7293?
Yes, Zope Management Interface versions up to and including 4.3.7 are vulnerable to CVE-2015-7293.