Description
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2006-1015)
MySQL CVE-2016-5627 Vulnerability (CVE-2016-5627)
WordPress Plugin Zephyr Project Manager Cross-Site Scripting (3.2.40)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2021-31618)
Oracle Database Server CVE-2008-0346 Vulnerability (CVE-2008-0346)