CVE-2013-7060

medium

Description

Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.

References

https://plone.org/security/20131210/path-leak

http://www.openwall.com/lists/oss-security/2013/12/12/3

http://www.openwall.com/lists/oss-security/2013/12/10/15

Details

Source: Mitre, NVD

Published: 2014-05-02

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium