Описание
The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.
It was discovered that Plone, included as a part of luci, allowed a remote anonymous user to change titles of content items due to improper permissions checks.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | conga | Affected | ||
| Red Hat Enterprise Linux 5 | conga | Fixed | RHSA-2014:1194 | 16.09.2014 |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=874649(Plone): Anonymous users can batch change titles of content items
2.6 Low
CVSS2
Связанные уязвимости
nvd
больше 11 лет назад
The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.
oracle-oval
больше 11 лет назад
ELSA-2014-1194: conga security and bug fix update (MODERATE)
2.6 Low
CVSS2