Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22889


Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.


Published

2024-03-06T00:15:52.633

Last Modified

2025-01-21T16:53:16.990

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-276
  • Type: Secondary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application plone plone 6.0.9 Yes

References