MEDIUM5.5
PYSEC-2026-1798
Phone information disclosure vulnerability
Details
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/plone
Introduced in:
0No fixed version published yet for plone (pip). Pin to a known-safe version or switch to an alternative.