PT-2020-1633 · Plone Foundation · Plone

Damiano Esposito

·

Published

2020-01-21

·

Updated

2022-05-24

·

CVE-2020-7941

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Plone versions 4.3 through 5.2.1
Description The issue is related to a privilege escalation problem in the plone.app.contenttypes package of the Plone content management system. This allows users to overwrite certain content using the PUT method without requiring write permission. The vulnerability can be exploited by a remote attacker to elevate their privileges.
Recommendations For Plone versions 4.3 through 5.2.1, consider restricting access to the plone.app.contenttypes package until a fix is available. As a temporary workaround, limit the ability of users to PUT content without proper write permissions to minimize the risk of exploitation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00839
CVE-2020-7941
GHSA-W6G9-XCCC-347H
PYSEC-2020-90

Affected Products

Plone