VDB
KO

PYSEC-2006-6

Details

Unspecified vulnerability in PlonePAS in Plone 2.5 and 2.5.1, when anonymous member registration is enabled, allows an attacker to "masquerade as a group."

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / plone
Introduced in: 2.5 Fixed in: 2.5.2
Fix pip install --upgrade 'plone>=2.5.2'

References