Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 1 min 107 bronnen 1 kritiek 1 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2013-4194

MEDIUM · 4.3 CVSS Gepubliceerd: CWE-200

Beschrijving

The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers to obtain sensitive information via a crafted URL, which reveals the installation path in an error message.

Vendors

Plone

Affected products

Plone

References