CVE-2016-7135: Path Traversal
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.
Other sources
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.
— GitHub
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7135?
CVE-2016-7135 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2016-7135?
To fix CVE-2016-7135, upgrade Plone CMS to version 4.3.12 or later for 4.3.x series or version 5.0.7 for 5.0.x series.
What systems are affected by CVE-2016-7135?
CVE-2016-7135 affects Plone CMS versions 4.2 through 4.3.11 and 5.0 through 5.0.6.
Can CVE-2016-7135 lead to data breaches?
Yes, CVE-2016-7135 could potentially lead to data breaches by allowing attackers to read arbitrary files.
Is there a patch available for CVE-2016-7135?
Yes, patches are available by upgrading to the latest versions of Plone CMS as mentioned in the remediation guidance.