First published: Wed Jun 26 2013(Updated: )
A file system path exposure flaw was found in the way Plone, a user friendly and powerful content management system, used to present certain error messages in the wysiwyg component. A remote attacker could provide a specially-crafted URL that, when processed would lead to exposure of file system path (for the selected component) of the Plone instance.
Affected Software | Affected Version | How to fix |
---|---|---|
Plone CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The REDHAT-BUG-978470 vulnerability is classified as a moderate severity issue due to the potential for file system path exposure.
To fix REDHAT-BUG-978470, update to the latest version of Plone that includes the security patches addressing this vulnerability.
The impact of REDHAT-BUG-978470 allows remote attackers to gain access to sensitive file system paths through specially-crafted URLs.
REDHAT-BUG-978470 affects certain versions of Plone prior to the security updates that address this flaw.
While user data may be safe, REDHAT-BUG-978470 poses a risk of leaking system file paths, potentially exposing system configuration details.