
This update protects security sensitive forms in Plone from cross site request forgery (CSRF) attacks.

This hotfix corrects a vulnerability in the statusmessages and linkintegrity modules, where unsafe network data was interpreted as python pickles. This allows an attacker to run arbitrary python code within the Zope/Plone process.

A vulnerability has been discovered in Zope, whereby misuse of certain types of HTTP GET could lead to elevated privileges. All Zope versions up to and including 2.10.2 are affected.

We will be entering a maintenance window this weekend to work on an upgrade of the Plone Help Center.

Plone was named best non-PHP-based open-source CMS by Packt Publishing for a second year in a row, winning a $2000 award for the Plone Foundation.

At its first meeting, the new Plone Foundation Board of Directors chose officers and appointed new advisory board members.

The Plone community needs you to help lead Plone into the future! Plone Foundation members will elect their next board of directors during Plone Conference 2009. Nominations for seats on the board are open until Monday, October 26th.

Plone the Plone Conference 2009 in Budapest is approaching!! Join Us!!
Lieu :Budapest
Date/heure :lundi 26 octobre 2009 09:00

The Plone community is featured prominently in an IT World article about open source sprints that includes interviews with Plone Foundation president Jon Stahl and PloneFormGen creator Steve McMahon.












