Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2000-10-13T04:00:00

Updated: 2024-08-08T05:28:41.342Z

Reserved: 2000-09-19T00:00:00

Link: CVE-2000-0725

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2000-10-20T04:00:00.000

Modified: 2008-09-10T19:05:42.353

Link: CVE-2000-0725

cve-icon Redhat

Severity :

Publid Date: 2000-08-10T00:00:00Z

Links: CVE-2000-0725 - Bugzilla