CVE-2026-28413 PUBLISHED

Products.isurlinportal: Possible open redirect when using more than 2 forward slashes

Assigner: GitHub_M
Reserved: 27.02.2026 Published: 05.03.2026 Updated: 06.03.2026

Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor plone
Product Products.isurlinportal
Versions
  • Version < 4.0.0 is affected
  • Version < 3.1.0 is affected
  • Version < 2.1.0 is affected

References

Problem Types

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') CWE