CVE-2026-28413 | plone Products.isurlinportal 2.0.x/3.0.x/3.x /login came_from redirect (GHSA-43gx-6gv6-3jcp)
A vulnerability identified as problematic has been detected in plone Products.isurlinportal 2.0.x/3.0.x/3.x. Affected by this issue is some unknown functionality of the file /login. The manipulation of the argument came_from leads to open redirect.
This vulnerability is referenced as CVE-2026-28413. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.