GHSA-jcwh-rj6j-vm75

Suggest an improvement
Source
https://github.com/advisories/GHSA-jcwh-rj6j-vm75
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jcwh-rj6j-vm75/GHSA-jcwh-rj6j-vm75.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-jcwh-rj6j-vm75
Aliases
  • CVE-2006-1711
Published
2022-05-01T06:52:02Z
Modified
2024-02-12T16:27:12.495917Z
Summary
Plone allows remote users to modify arbitrary portraits
Details

Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.

Database specific
{
    "nvd_published_at": "2006-04-11T18:06:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-12T16:10:44Z"
}
References

Affected packages

PyPI / plone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.6

Database specific

{
    "last_known_affected_version_range": "<= 2.0.5"
}

PyPI / plone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1.0
Last affected
2.1.2

PyPI / plone

Package

Affected ranges

Affected versions

2.*

2.5-beta1