Lucene search

K
osvGoogleOSV:GHSA-4MG4-WVMX-5332
HistoryJun 15, 2021 - 4:11 p.m.

Server-Side Request Forgery in Plone

2021-06-1516:11:47
Google
osv.dev
11
plone
ssrf
ical url
remote authenticated managers

EPSS

0.001

Percentile

35.3%

Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line of a file.

EPSS

0.001

Percentile

35.3%

Related for OSV:GHSA-4MG4-WVMX-5332