CVE-2013-4194 Information
Feb 14, 2021
cve
Description
The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1 4.2.x through 4.2.5 and 4.3.x through 4.3.1 allows remote attackers to obtain sensitive information via a crafted URL which reveals the installation path in an error message.
Reference
http://plone.org/products/plone/security/advisories/20130618-announcement http://plone.org/products/plone-hotfix/releases/20130618 http://seclists.org/oss-sec/2013/q3/261 https://bugzilla.redhat.com/show_bug.cgi?id=978470
Share on: