PT-2000-1992 · Zope · Zope
Published
2000-12-18
·
Updated
2022-04-30
·
CVE-2000-1212
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Zope versions 2.2.0 through 2.2.4
Description
The issue allows attackers with DTML editing privileges to modify the raw data of Image and File objects due to insufficient protection of a data updating method.
Recommendations
For versions 2.2.0 through 2.2.4, consider restricting DTML editing privileges to minimize the risk of exploitation until a patch is available.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zope