Description
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1032-1 | New zope-cmfplone packages fix unprivileged data manipulation |
Github GHSA |
GHSA-jcwh-rj6j-vm75 | Plone allows remote users to modify arbitrary portraits |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T17:19:49.405Z
Reserved: 2006-04-11T00:00:00.000Z
Link: CVE-2006-1711
No data.
Status : Modified
Published: 2006-04-11T18:06:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-1711
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Github GHSA