CVE-2016-7135: Plone
Medium severity, CVSS 4.9. EPSS: 2.6% chance of exploitation in the next 30 days.
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a .. (dot dot) in the path parameter in a getFile action to Plone/++theme++barceloneta/@@plone.resourceeditor.filemanager-actions.
Affected products
- Plone Plone: version 4.2 only; version 4.2.1 only; version 4.2.2 only; version 4.2.3 only; version 4.2.4 only; version 4.2.5 only; …
Published 2017-03-07. Last modified 2026-06-17.