PT-2000-1658 · Zope · Zope

Published

2000-10-20

·

Updated

2022-04-30

·

CVE-2000-0725

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zope versions prior to 2.2.1
Description The issue allows users who can edit DTML to add or modify roles by modifying the roles list included in a request, due to improper access restriction to the getRoles method.
Recommendations For versions prior to 2.2.1, update to version 2.2.1 or later to resolve the issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2000-0725
GHSA-9CMQ-PJ6P-HGWF

Affected Products

Zope