Looking for the vulnerability index of Invicti's legacy products?
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4193) - Vulnerability Database

Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4193)

Description

typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.

References

Related Vulnerabilities