—
PYSEC-2014-56
Details
sendto.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to spoof emails via unspecified vectors.
Are you affected?
Enter the version of the package you're using.