{"id":"CVE-2013-7060","aliases":["PYSEC-2014-65","PYSEC-2014-67"],"url":"https://o3.security/vulnerability/CVE-2013-7060","summary":"Plone Filesystem path information leak","details":"Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.","published":"2022-05-17T04:41:01Z","modified":"2024-10-15T18:01:10.469655Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"plone","fixedVersion":"4.3.3"},{"ecosystem":"PyPI","name":"products-cmfplone","fixedVersion":"4.3.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7060"},{"type":"PACKAGE","url":"https://github.com/plone/Plone"},{"type":"WEB","url":"https://github.com/plone/Products.CMFPlone/blob/b08a45bc12b1bd42411f1130a487a7a242349ea0/Products/CMFPlone/FactoryTool.py#L272-L274"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2014-65.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/products-cmfplone/PYSEC-2014-67.yaml"},{"type":"WEB","url":"https://plone.org/security/20131210/path-leak"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/12/10/15"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/12/12/3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-10-15T18:01:10.469655Z"}}