CVE-2016-7137

medium
Published 2022-05-14 · Modified 2023-11-08
CVSS v3
6.1
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2
5.8
VIR risk
6.1

Description

Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.

Predictions

Exploit likelihood
71%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://plone.org/security/hotfix/20160830/open-redirection-in-plone

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2016/09/05/5

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2016/09/05/4

Package impact

EcosystemPackageVulnerableFixed
python PyPIplone>=5.0,<=5.0.6
python PyPIplone>=4.0,<=4.3.11
python PyPIplone>=3.3,<=3.3.6
python PyPIplone>=3.3,<4.0a15.0.7

Application impact

VendorProductVersionsFixed
ploneplone3.3
ploneplone3.3.1
ploneplone3.3.2
ploneplone3.3.3
ploneplone3.3.4
ploneplone3.3.5
ploneplone3.3.6
ploneplone4.0
ploneplone4.0.1
ploneplone4.0.2
ploneplone4.0.3
ploneplone4.0.4
ploneplone4.0.5
ploneplone4.0.7
ploneplone4.0.8
ploneplone4.0.9
ploneplone4.0.10
ploneplone4.1
ploneplone4.1.1
ploneplone4.1.2
ploneplone4.1.3
ploneplone4.1.4
ploneplone4.1.5
ploneplone4.1.6
ploneplone4.2
ploneplone4.2.1
ploneplone4.2.2
ploneplone4.2.3
ploneplone4.2.4
ploneplone4.2.5
ploneplone4.2.6
ploneplone4.2.7
ploneplone4.3
ploneplone4.3.1
ploneplone4.3.2
ploneplone4.3.3
ploneplone4.3.4
ploneplone4.3.5
ploneplone4.3.6
ploneplone4.3.7
ploneplone4.3.8
ploneplone4.3.9
ploneplone4.3.10
ploneplone4.3.11
ploneplone5.0
ploneplone5.0.1
ploneplone5.0.2
ploneplone5.0.3
ploneplone5.0.4
ploneplone5.0.5
ploneplone5.0.6
ploneplone5.1a1

References

CWEs

CWE-601

Verify integrity in audit chain (admin only). AS-IS.