CVE-2006-4249

Plone 2.5-2.5.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in PlonePAS in Plone 2.5 and 2.5.1, when anonymous member registration is enabled, allows an attacker to "masquerade as a group."

References (5)

Core 5
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21460
Patch, Vendor Advisory x_refsource_confirm
http://plone.org/about/security/advisories/cve-2006-4249/
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23240
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30762
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4878

Scores

EPSS 0.0100
EPSS Percentile 59.0%

Details

Status published
Products (3)
plone/plone 2.5
plone/plone 2.5.1
pypi/Plone 2.5 - 2.5.2PyPI
Published Dec 07, 2006
Tracked Since Feb 18, 2026