CVE-2013-4194: Plone

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers to obtain sensitive information via a crafted URL, which reveals the installation path in an error message.

Affected products

  • Plone Plone: version 4.3 only; version 4.3.1 only; version 4.2 only; version 4.2.1 only; version 4.2.2 only; version 4.2.3 only; …

Published 2014-03-11. Last modified 2026-06-16.