Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Plone Isurlinportal
cpe:2.3:a:plone:isurlinportal:*:*:*:*:*:plone:*:*
|
— |
2.1.0
|
|
Plone Isurlinportal
cpe:2.3:a:plone:isurlinportal:*:*:*:*:*:plone:*:*
|
3.0.0
|
3.1.0
|
|
Plone Isurlinportal
cpe:2.3:a:plone:isurlinportal:4.0.0:alpha1:*:*:*:plone:*:*
|
— | — |