CVE-2024-22889
EUVD-2024-104006.03.2024, 00:15
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| plone | plone | 6.0.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration