CVE-2026-28413
EUVD-2026-987205.03.2026, 21:16
Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| plone | isurlinportal | 𝑥 < 2.1.0 |
| plone | isurlinportal | 3.0.0 ≤ 𝑥 < 3.1.0 |
| plone | isurlinportal | 4.0.0:alpha1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration