Moderate severityNVD Advisory· Published May 2, 2014· Updated Jun 17, 2026
CVE-2013-7061
CVE-2013-7061
Description
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PlonePyPI | >= 3.3b1, < 4.3.3 | 4.3.3 |
Products.CMFPlonePyPI | >= 3.3, < 4.3.3 | 4.3.3 |
Affected products
35- ghsa-coords2 versions
>= 3.3b1, < 4.3.3+ 1 more
- (no CPE)range: >= 3.3b1, < 4.3.3
- (no CPE)range: >= 3.3, < 4.3.3
cpe:2.3:a:plone:plone:3.3:*:*:*:*:*:*:*+ 32 more
- cpe:2.3:a:plone:plone:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:3.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:3.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:3.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:3.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.3:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:plone:plone:4.3.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-4vr8-r7qr-fpvqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-7061ghsaADVISORY
- plone.org/security/20131210/catalogue-exposurenvdVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2013/12/10/15nvdWEB
- www.openwall.com/lists/oss-security/2013/12/12/3nvdWEB
- github.com/plone/Products.CMFPlone/commit/a6a3e50f759da7e7ca46e50777a35e51f4d8ed48ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2014-66.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/products-cmfplone/PYSEC-2014-68.yamlghsaWEB
- pypi.org/project/Products.PloneHotfix20131210ghsaWEB
News mentions
0No linked articles in our index yet.