PT-2014-2327 · Plone+1 · Plone+1

Published

2014-09-16

·

Updated

2023-02-13

·

CVE-2012-5500

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Plone versions prior to 4.2.3 Plone version 4.3 before beta 1
Description The issue allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request. This is possible due to a flaw in the batch id change script, specifically the renameObjectsByPaths.py script.
Recommendations For Plone versions prior to 4.2.3, update to version 4.2.3 or later. For Plone version 4.3 before beta 1, update to beta 1 or later. As a temporary workaround, consider restricting access to the renameObjectsByPaths.py script until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2012-5500
GHSA-2Q75-F7CP-W86Q
PYSEC-2014-42
RHSA-2014:1194
RHSA-2014_1194

Affected Products

Plone
Red Hat