PT-2017-8448 · Plone · Plone

Published

2017-02-24

·

Updated

2022-05-17

·

CVE-2016-4041

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Plone versions 4.0 through 5.1a1
Description The issue allows remote attackers to gain webdav access via unspecified vectors due to the lack of security declarations for Dexterity content-related WebDAV requests.
Recommendations For Plone versions 4.0 through 5.1a1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4041
GHSA-QQGJ-22GR-73VX
PYSEC-2017-55

Affected Products

Plone