{"id":"CVE-2000-1212","aliases":["GHSA-7whr-j8vf-r4wj","PYSEC-2026-756"],"title":"Zope allows attackers to modify raw image and file data","summary":"Zope allows attackers to modify raw image and file data","severity":"medium","vendor":"zope","product":"zope","ecosystem":"pip","affected":["zope >= 2.2.0, <= 2.2.4"],"published":"2022-04-30","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7whr-j8vf-r4wj","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2000-1212"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5778"},{"url":"https://web.archive.org/web/20020117134418/http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000365"},{"url":"http://www.debian.org/security/2001/dsa-007"},{"url":"http://www.redhat.com/support/errata/RHSA-2000-135.html"},{"url":"http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert"}],"tags":["osv","pip"],"epss":0.01542,"epssPercentile":0.73414,"ingestedAt":"2026-07-08T18:25:47.242Z","slug":"CVE-2000-1212","body":"## Overview\n\nZope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.\n\n## Affected packages\n\n- `zope >= 2.2.0, <= 2.2.4`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}