{"id":"CVE-2006-1711","aliases":["GHSA-jcwh-rj6j-vm75","PYSEC-2026-733"],"title":"Plone allows remote users to modify arbitrary portraits","summary":"Plone allows remote users to modify arbitrary portraits","severity":"medium","vendor":"plone","product":"plone","ecosystem":"pip","affected":["plone < 2.0.6","plone >= 2.1.0, <= 2.1.2","plone"],"patched":["plone 2.0.6"],"published":"2022-05-01","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jcwh-rj6j-vm75","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1711"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25781"},{"url":"https://github.com/plone/Plone"},{"url":"https://web.archive.org/web/20060412111111/https://dev.plone.org/plone/ticket/5432"},{"url":"https://web.archive.org/web/20060422195724/http://www.securityfocus.com/bid/17484"},{"url":"http://www.debian.org/security/2006/dsa-1032"}],"tags":["osv","pip","exploit-available"],"epss":0.03923,"epssPercentile":0.89902,"exploitAvailable":true,"ingestedAt":"2026-07-08T18:25:50.645Z","exploits":{"exploitdb":true,"checkedAt":"2026-09-21T15:24:34.869Z"},"slug":"CVE-2006-1711","body":"## Overview\n\nPlone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.\n\n## Affected packages\n\n- `plone < 2.0.6`\n- `plone >= 2.1.0, <= 2.1.2`\n- `plone`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `plone 2.0.6`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":27.5,"likelihood":0.8,"exploitation":12,"ransomware":0},"changes":[]}