[+] Credits: hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/AS-ZOPE-CSRF.txt Vendor: ================================ www.zope.org plone.org Product: ================================ Zope Management Interface 4.3.7 Zope is a Python-based application server for building secure and highly scalable web applications. Plone Is a Content Management System built on top of the open source application server Zope and the accompanying Content Management Framework. Vulnerability Type: =================== Cross site request forgery (CSRF) Multiple CSRF (cross-site request forgery) vulnerabilities in the ZMI (Zope Management Interface). Patches to Zope and Plone for multiple CSRF issues. https://plone.org/security/20151006/multiple-csrf-vulnerabilities-in-zope https://plone.org/products/plone/security/advisories/security-vulnerability-20151006-csrf CVE Reference: ============== NA Vulnerability Details: ===================== Security vulnerability: 20151006 - CSRF ZMI is mostly unprotected from CSRF vulnerabilities. Versions affected 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.2, 4.3.1, 4.3, 4.2.7, 4.2.6, 4.2.5, 4.2.4, 4.2.3, 4.2.2, 4.2.1, 4.2 4.1.6, 4.1.5, 4.1.4, 4.1.3, 4.1.2, 4.1.1, 4.1, 4.0.9, 4.0.7, 4.0.5, 4.0.4, 4.0.3, 4.0.2, 4.0.1, 4.0, 3.3.6 3.3.5, 3.3.4. 3.3.3, 3.3.2, 3.3.1, 3.3 All versions of Plone prior to 5.x are vulnerable. Fixed by Nathan Van Gheem, of the Plone Security Team Coordinated by Plone Security Team patch was released and is available from https://pypi.python.org/pypi/plone4.csrffixes Exploit code(s): ===============