CVE-2024-23756

HIGH

Plone 5.2.13 - Unauthenticated RCE

Title source: llm
STIX 2.1

Description

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

Status published
Products (1)
plone/plone 5.2.13
Published Feb 08, 2024
Tracked Since Feb 18, 2026