Plone 'mail_password.py' Access Bypass Vulnerability
BID:61958
Info
Plone 'mail_password.py' Access Bypass Vulnerability
| Bugtraq ID: | 61958 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-4198 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2013 12:00AM |
| Updated: | Mar 19 2015 09:42AM |
| Credit: | Matthew Wilkes |
| Vulnerable: |
Plone Plone 4.1.3 Plone Plone 4.0.8 Plone Plone 4.0.7 Plone Plone 3.3.5 Plone Plone 3.3.4 Plone Plone 3.3.3 Plone Plone 3.3.2 Plone Plone 3.3.1 Plone Plone 3.2.3 Plone Plone 3.2.2 Plone Plone 3.1.6 Plone Plone 3.1.4 Plone Plone 3.0.5 Plone Plone 3.0.4 Plone Plone 3.0.3 Plone Plone 3.0.2 Plone Plone 3.0.1 Plone Plone 2.5.5 Plone Plone 2.5.4 Plone Plone 2.5.1 Plone Plone 2.1.2 Plone Plone 2.0.5 Plone Plone 2.0.4 Plone Plone 4.2a2 Plone Plone 4.2a1 Plone Plone 4.2 Plone Plone 4.1 Plone Plone 4.0.9 Plone Plone 4.0.6.1 Plone Plone 4.0.5 Plone Plone 4.0.4 Plone Plone 4.0.3 Plone Plone 4.0.2 Plone Plone 4.0.1 Plone Plone 4.0 Plone Plone 3.3.2 Plone Plone 3.3.1 Plone Plone 3.3 Plone Plone 3.3 Plone Plone 3.2.3 Plone Plone 3.2.2 Plone Plone 3.2.1 Plone Plone 3.2 Plone Plone 3.1.7 Plone Plone 3.1.6 Plone Plone 3.1.5.1 Plone Plone 3.1.3 Plone Plone 3.1.2 Plone Plone 3.1.1 Plone Plone 3.1 Plone Plone 3.0.6 Plone Plone 3.0 Plone Plone 2.5-beta1 Plone Plone 2.5 Plone Plone 2.1.3 Plone Plone 2.1.1 Plone Plone 2.1 Plone Plone 2.0.2 Plone Plone 2.0.1 Plone Plone 2.0 Plone Plone 1.0.6 Plone Plone 1.0.5 Plone Plone 1.0.4 Plone Plone 1.0.3 Plone Plone 1.0.2 Plone Plone 1.0.1 |
| Not Vulnerable: | |
Discussion
Plone 'mail_password.py' Access Bypass Vulnerability
Plone is prone to an access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Note: This issue was previously covered in BID 61544 (Plone Multiple Remote Security Vulnerabilities), but has been moved to its own record for better documentation.
Plone is prone to an access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Note: This issue was previously covered in BID 61544 (Plone Multiple Remote Security Vulnerabilities), but has been moved to its own record for better documentation.
Exploit / POC
Plone 'mail_password.py' Access Bypass Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Plone 'mail_password.py' Access Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.