// For flags

CVE-2017-1000481

 

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse this by letting you click on a specially crafted link. You would login, and get redirected to the site of the attacker, letting you think that you are still on the original Plone site. Or some javascript of the attacker could be executed. Most of these types of attacks are already blocked by Plone, using the `isURLInPortal` check to make sure we only redirect to a page on the same Plone site. But a few more ways of tricking Plone into accepting a malicious link were discovered, and fixed with this hotfix.

Cuando visitas una página en la que necesitas iniciar sesión, Plone 2.5-5.1rc1 te envía al formulario de inicio de sesión con un parámetro "came_from" establecido para la url anterior. Tras iniciar sesión, se te redirige a la página que intentabas ver antes. Un atacante podría intentar provecharse de esto dejando que hagas clic en un enlace especialmente manipulado. Al iniciar sesión, se te redirigiría al sitio del atacante, dejando que creas que sigues en el sitio de Plone original. O se podría ejecutar también JavaScript del atacante. La mayoría de estos ataques ya están bloqueados por Plone, empleando la comprobación "isURLInPortal" para asegurarse de que solo redirigimos a una página en el mismo sitio de Plone. Sin embargo, se han descubierto más formas de engañar a Plone para que acepte un enlace malicioso, que se han solucionado con este hotfix.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-01-03 CVE Reserved
  • 2018-01-03 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
2.5.5
Search vendor "Plone" for product "Plone" and version "2.5.5"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
3.3
Search vendor "Plone" for product "Plone" and version "3.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
3.3.1
Search vendor "Plone" for product "Plone" and version "3.3.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
3.3.2
Search vendor "Plone" for product "Plone" and version "3.3.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
3.3.3
Search vendor "Plone" for product "Plone" and version "3.3.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
3.3.4
Search vendor "Plone" for product "Plone" and version "3.3.4"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
3.3.5
Search vendor "Plone" for product "Plone" and version "3.3.5"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
3.3.6
Search vendor "Plone" for product "Plone" and version "3.3.6"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0
Search vendor "Plone" for product "Plone" and version "4.0"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.1
Search vendor "Plone" for product "Plone" and version "4.0.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.2
Search vendor "Plone" for product "Plone" and version "4.0.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.3
Search vendor "Plone" for product "Plone" and version "4.0.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.4
Search vendor "Plone" for product "Plone" and version "4.0.4"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.5
Search vendor "Plone" for product "Plone" and version "4.0.5"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.7
Search vendor "Plone" for product "Plone" and version "4.0.7"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.8
Search vendor "Plone" for product "Plone" and version "4.0.8"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.9
Search vendor "Plone" for product "Plone" and version "4.0.9"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.10
Search vendor "Plone" for product "Plone" and version "4.0.10"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.1
Search vendor "Plone" for product "Plone" and version "4.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.1.1
Search vendor "Plone" for product "Plone" and version "4.1.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.1.2
Search vendor "Plone" for product "Plone" and version "4.1.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.1.3
Search vendor "Plone" for product "Plone" and version "4.1.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.1.4
Search vendor "Plone" for product "Plone" and version "4.1.4"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.1.5
Search vendor "Plone" for product "Plone" and version "4.1.5"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.1.6
Search vendor "Plone" for product "Plone" and version "4.1.6"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2
Search vendor "Plone" for product "Plone" and version "4.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2.1
Search vendor "Plone" for product "Plone" and version "4.2.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2.2
Search vendor "Plone" for product "Plone" and version "4.2.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2.3
Search vendor "Plone" for product "Plone" and version "4.2.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2.4
Search vendor "Plone" for product "Plone" and version "4.2.4"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2.5
Search vendor "Plone" for product "Plone" and version "4.2.5"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2.6
Search vendor "Plone" for product "Plone" and version "4.2.6"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2.7
Search vendor "Plone" for product "Plone" and version "4.2.7"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3
Search vendor "Plone" for product "Plone" and version "4.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.1
Search vendor "Plone" for product "Plone" and version "4.3.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.2
Search vendor "Plone" for product "Plone" and version "4.3.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.3
Search vendor "Plone" for product "Plone" and version "4.3.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.4
Search vendor "Plone" for product "Plone" and version "4.3.4"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.5
Search vendor "Plone" for product "Plone" and version "4.3.5"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.6
Search vendor "Plone" for product "Plone" and version "4.3.6"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.7
Search vendor "Plone" for product "Plone" and version "4.3.7"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.8
Search vendor "Plone" for product "Plone" and version "4.3.8"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.9
Search vendor "Plone" for product "Plone" and version "4.3.9"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.10
Search vendor "Plone" for product "Plone" and version "4.3.10"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.11
Search vendor "Plone" for product "Plone" and version "4.3.11"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.12
Search vendor "Plone" for product "Plone" and version "4.3.12"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.14
Search vendor "Plone" for product "Plone" and version "4.3.14"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.3.15
Search vendor "Plone" for product "Plone" and version "4.3.15"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0
Search vendor "Plone" for product "Plone" and version "5.0"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0
Search vendor "Plone" for product "Plone" and version "5.0"
rc1
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0
Search vendor "Plone" for product "Plone" and version "5.0"
rc2
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0
Search vendor "Plone" for product "Plone" and version "5.0"
rc3
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.1
Search vendor "Plone" for product "Plone" and version "5.0.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.2
Search vendor "Plone" for product "Plone" and version "5.0.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.3
Search vendor "Plone" for product "Plone" and version "5.0.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.4
Search vendor "Plone" for product "Plone" and version "5.0.4"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.5
Search vendor "Plone" for product "Plone" and version "5.0.5"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.6
Search vendor "Plone" for product "Plone" and version "5.0.6"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.7
Search vendor "Plone" for product "Plone" and version "5.0.7"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.8
Search vendor "Plone" for product "Plone" and version "5.0.8"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.0.9
Search vendor "Plone" for product "Plone" and version "5.0.9"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.1
Search vendor "Plone" for product "Plone" and version "5.1"
a1
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.1
Search vendor "Plone" for product "Plone" and version "5.1"
a2
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.1
Search vendor "Plone" for product "Plone" and version "5.1"
b2
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.1
Search vendor "Plone" for product "Plone" and version "5.1"
b3
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.1
Search vendor "Plone" for product "Plone" and version "5.1"
b4
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
5.1
Search vendor "Plone" for product "Plone" and version "5.1"
rc1
Affected