PT-2020-1633 · Plone Foundation · Plone
Damiano Esposito
·
Published
2020-01-21
·
Updated
2022-05-24
·
CVE-2020-7941
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Plone versions 4.3 through 5.2.1
Description
The issue is related to a privilege escalation problem in the plone.app.contenttypes package of the Plone content management system. This allows users to overwrite certain content using the PUT method without requiring write permission. The vulnerability can be exploited by a remote attacker to elevate their privileges.
Recommendations
For Plone versions 4.3 through 5.2.1, consider restricting access to the plone.app.contenttypes package until a fix is available. As a temporary workaround, limit the ability of users to PUT content without proper write permissions to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plone