Plone < 4.2.6 / 4.3.x < 4.3.2 Multiple Vulnerabilities (HF 20130618)

medium Nessus Plugin ID 329026

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Plone installed on the remote host is prior to 4.3.2. It is, therefore, affected by the following vulnerabilities:

- traverser.py allows remote attackers with administrator privileges to cause a denial of service (infinite loop and resource consumption) via unspecified vectors related to 'retrieving information for certain resources'. (CVE-2013-4188)

- Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone allow remote authenticated users with administrator access to a subtree to access nodes above the subtree via unknown vectors. (CVE-2013-4189)

- Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) request.py in Plone allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
(CVE-2013-4190)

- zip.py allows remote attackers to obtain sensitive information by reading a generated archive.
(CVE-2013-4191)

- sendto.py allows remote authenticated users to spoof emails via unspecified vectors. (CVE-2013-4192)

- typeswidget.py allows remote attackers to hide fields on the forms via a crafted URL. (CVE-2013-4193)

- The WYSIWYG component (wysiwyg.py) allows remote attackers to obtain sensitive information via a crafted URL, which reveals the installation path in an error message. (CVE-2013-4194)

- Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. (CVE-2013-4195)

- The object manager implementation (objectmanager.py) allows remote attackers to obtain sensitive information via a crafted request. (CVE-2013-4196)

- member_portrait.py allows remote authenticated users to modify or delete portraits of other users via unspecified vectors. (CVE-2013-4197)

- mail_password.py allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality. (CVE-2013-4198)

- (1) cb_decode.py and (2) linkintegrity.py in Plone allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed). (CVE-2013-4199)

- The isURLInPortal method in the URLTool class in in_portal.py in Plone treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login_sites filtering property, redirect users to arbitrary web sites, and conduct phishing attacks via a space before a URL in the 'next' parameter to acl_users/credentials_cookie_auth/require_login. (CVE-2013-4200)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number. Since a vendor hotfix (PloneHotfix20130618) may remediate this without a version upgrade, this plugin only reports when running in Paranoid mode.

Solution

Apply the vendor hotfix (Products.PloneHotfix20130618), or upgrade to Plone version 4.2.6, 4.3.2, or later.

See Also

https://plone.org/security/hotfix/20130618

http://www.nessus.org/u?0ee3c4bf

http://www.nessus.org/u?1db9523d

http://www.openwall.com/lists/oss-security/2013/08/01/2

Plugin Details

Severity: Medium

ID: 329026

File Name: plone_HF_20130618.nasl

Version: 1.2

Type: Local

Family: Misc.

Published: 7/22/2026

Updated: 7/23/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.04

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2013-4189

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:plone:plone

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/18/2013

Vulnerability Publication Date: 6/18/2013

Reference Information

CVE: CVE-2013-4188, CVE-2013-4189, CVE-2013-4190, CVE-2013-4191, CVE-2013-4192, CVE-2013-4193, CVE-2013-4194, CVE-2013-4195, CVE-2013-4196, CVE-2013-4197, CVE-2013-4198, CVE-2013-4199, CVE-2013-4200