Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Plone MembershipTool 访问控制绕过漏洞
Vulnerability Description
Plone 2.0.5、2.1.2 及2.5-beta1版本不能限制对方法(1)changeMemberPortrait、(2)deletePersonalPortrait和(3)testCurrentPassword的访问。这使得远程攻击者可以修改头像。
CVSS Information
N/A
Vulnerability Type
N/A