Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2014-0084 | Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API. |
![]() |
GHSA-4vr8-r7qr-fpvq | Plone Privilege escalation through exposed underlying API |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T17:53:46.062Z
Reserved: 2013-12-11T00:00:00
Link: CVE-2013-7061

No data.

Status : Deferred
Published: 2014-05-02T14:55:05.417
Modified: 2025-04-12T10:46:40.837
Link: CVE-2013-7061


No data.