MEDIUM 5.5
GHSA-xg5p-8wg5-rhxm
Phone information disclosure vulnerability
Details
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / plone
Introduced in:
0 No fixed version published yet for plone (pip). Pin to a known-safe version or switch to an alternative.