Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Daniel Kraft

Researcher fromd9t.de
#39381of 53,635
6.9Total CVSS
Vulnerabilities · 1
PT-2014-2324
6.9
2014-09-16
Plone Foundation · Plone · CVE-2012-5497
**Name of the Vulnerable Software and Affected Versions** Plone versions prior to 4.2.3 Plone versions 4.3 prior to beta 1 **Description** The issue allows remote attackers to enumerate user account names via a crafted URL. This is related to the membership tool.py script. **Recommendations** For Plone versions prior to 4.2.3, update to version 4.2.3 or later. For Plone versions 4.3 prior to beta 1, update to beta 1 or later.