CVE Vulnerabilities

CVE-2006-1711

Published: Apr 11, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.

Affected Software

Name Vendor Start Version End Version
Plone Plone 2.0.5 (including) 2.0.5 (including)
Plone Plone 2.1.2 (including) 2.1.2 (including)
Plone Plone 2.5_beta1 (including) 2.5_beta1 (including)

References