A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
{
"cpe": "cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "4.3.0"
},
{
"last_affected": "5.2.1"
}
],
"source": "CPE_RANGE"
}