CVE-2016-7137
Last modified
CVE-2016-7137 is a vulnerability of currently unknown severity. Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Plone | Plone | 3.3 |
| Plone | Plone | 3.3.1 |
| Plone | Plone | 3.3.2 |
| Plone | Plone | 3.3.3 |
| Plone | Plone | 3.3.4 |
| Plone | Plone | 3.3.5 |
| Plone | Plone | 3.3.6 |
| Plone | Plone | 4.0 |
| Plone | Plone | 4.0.1 |
| Plone | Plone | 4.0.2 |
| Plone | Plone | 4.0.3 |
| Plone | Plone | 4.0.4 |
| Plone | Plone | 4.0.5 |
| Plone | Plone | 4.0.7 |
| Plone | Plone | 4.0.8 |
| Plone | Plone | 4.0.9 |
| Plone | Plone | 4.0.10 |
| Plone | Plone | 4.1 |
| Plone | Plone | 4.1.1 |
| Plone | Plone | 4.1.2 |
| Plone | Plone | 4.1.3 |
| Plone | Plone | 4.1.4 |
| Plone | Plone | 4.1.5 |
| Plone | Plone | 4.1.6 |
| Plone | Plone | 4.2 |
| Plone | Plone | 4.2.1 |
| Plone | Plone | 4.2.2 |
| Plone | Plone | 4.2.3 |
| Plone | Plone | 4.2.4 |
| Plone | Plone | 4.2.5 |
| Plone | Plone | 4.2.6 |
| Plone | Plone | 4.2.7 |
| Plone | Plone | 4.3 |
| Plone | Plone | 4.3.1 |
| Plone | Plone | 4.3.2 |
| Plone | Plone | 4.3.3 |
| Plone | Plone | 4.3.4 |
| Plone | Plone | 4.3.5 |
| Plone | Plone | 4.3.6 |
| Plone | Plone | 4.3.7 |
| Plone | Plone | 4.3.8 |
| Plone | Plone | 4.3.9 |
| Plone | Plone | 4.3.10 |
| Plone | Plone | 4.3.11 |
| Plone | Plone | 5.0 |
| Plone | Plone | 5.0.1 |
| Plone | Plone | 5.0.2 |
| Plone | Plone | 5.0.3 |
| Plone | Plone | 5.0.4 |
| Plone | Plone | 5.0.5 |
Showing 50 of 52 affected configurations. See NVD for the full list.
References
- http://packetstormsecurity.com/files/139110/Plone-CMS-4.3.11-5.0.6-XSS-Traversal-Open-Redirection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Oct/80Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2016/09/05/4Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/09/05/5Mailing List, Patch, Third Party Advisory
- http://packetstormsecurity.com/files/139110/Plone-CMS-4.3.11-5.0.6-XSS-Traversal-Open-Redirection.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Oct/80Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2016/09/05/4Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/09/05/5Mailing List, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-7137?
How severe is CVE-2016-7137?
How do I fix CVE-2016-7137?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-7131ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 a…7.5
- CVE-2016-7132ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 a…7.5
- CVE-2016-7133Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedi…
- CVE-2016-7134ext/curl/interface.c in PHP 7.x before 7.0.10 does not work …
- CVE-2016-7135Directory traversal vulnerability in Plone CMS 5.x through 5…
- CVE-2016-7136z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.…
- CVE-2016-7138Cross-site scripting (XSS) vulnerability in the URL checking…
- CVE-2016-7139Cross-site scripting (XSS) vulnerability in an unspecified p…
- CVE-2016-7140Multiple cross-site scripting (XSS) vulnerabilities in the Z…
- CVE-2016-7141curl and libcurl before 7.50.2, when built with NSS and the …
- CVE-2016-7142The m_sasl module in InspIRCd before 2.0.23, when used with …
- CVE-2016-7143The m_authenticate function in modules/m_sasl.c in Charybdis…
Are you affected by CVE-2016-7137?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
