CVE-2016-7137: Medium severity plone cms vulnerability
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) camefrom parameter to /loginform.
Other sources
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) camefrom parameter to /loginform.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7137?
The severity of CVE-2016-7137 is classified as medium, as it allows open redirection vulnerabilities that can facilitate phishing attacks.
How do I fix CVE-2016-7137?
To patch CVE-2016-7137, update Plone CMS to version 5.0.7 or later, or 4.3.12 or later.
Which versions are affected by CVE-2016-7137?
CVE-2016-7137 affects Plone CMS versions 5.0.6 and earlier, 4.3.11 and earlier, and 3.3.6 and earlier.
What are the implications of CVE-2016-7137?
The implications of CVE-2016-7137 include the potential for attackers to redirect users to malicious websites.
What type of vulnerability is CVE-2016-7137?
CVE-2016-7137 is categorized as an open redirect vulnerability.