Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hch-v5pq-x4qp

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8
CVSS3: 9.1

Описание

Plone allows anonymous users to reset any users password through the web via Password Reset Tool

Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of other users, related to "an erroneous security declaration."

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 2.5, < 2.5.1

2.5.1

EPSS

Процентиль: 55%
0.00333
Низкий

8 High

CVSS4

9.1 Critical

CVSS3

Связанные уязвимости

ubuntu
почти 19 лет назад

Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of other users, related to "an erroneous security declaration."

nvd
почти 19 лет назад

Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of other users, related to "an erroneous security declaration."

debian
почти 19 лет назад

Unspecified vulnerability in the Password Reset Tool before 0.4.1 on P ...

EPSS

Процентиль: 55%
0.00333
Низкий

8 High

CVSS4

9.1 Critical

CVSS3