CVE-2013-4198

Plone 2.1-4.1, 4.2.x-4.2.5, 4.3.x-4.3.1 - Authenticated Password Change Bypass via Forgotten Password Email

Title source: llm
STIX 2.1

Description

mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.

References (4)

Core 4
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=978480
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q3/261

Scores

EPSS 0.0112
EPSS Percentile 62.7%

Details

CWE
CWE-264
Status published
Products (50)
plone/plone 2.1
plone/plone 2.1.1
plone/plone 2.1.2
plone/plone 2.1.3
plone/plone 2.1.4
plone/plone 2.5
plone/plone 2.5.1
plone/plone 2.5.2
plone/plone 2.5.3
plone/plone 2.5.4
... and 40 more
Published Mar 11, 2014
Tracked Since Feb 18, 2026