Description
Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of other users, related to "an erroneous security declaration."
References (1)
Core 1
Core References
Patch x_refsource_confirm
http://plone.org/about/security/advisories/cve-2006-4247
Scores
EPSS
0.0100
EPSS Percentile
59.3%
Details
Status
published
Products (3)
plone/plone
2.5
plone/plone
2.5.1_rc
pypi/Plone
2.5 - 2.5.1PyPI
Published
Sep 29, 2006
Tracked Since
Feb 18, 2026