---
id: CVE-2000-0483
aliases:
  - GHSA-j5cc-3h6r-jqh4
  - PYSEC-2026-760
title: Zope DocumentTemplate package allows unauthenticated write
summary: Zope DocumentTemplate package allows unauthenticated write
severity: medium
vendor: zope
product: zope
ecosystem: pip
affected:
  - zope <= 2.2
published: '2022-05-03'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-j5cc-3h6r-jqh4'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2000-0483'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/4716'
  - url: >-
      https://web.archive.org/web/20000819120649/http://archives.neohapsis.com/archives/bugtraq/2000-06/0144.html
  - url: >-
      https://web.archive.org/web/20000819123924/http://archives.neohapsis.com/archives/bugtraq/2000-07/0412.html
  - url: >-
      https://web.archive.org/web/20010702023709/http://www.securityfocus.com/bid/1354
  - url: 'http://www.redhat.com/support/errata/RHSA-2000-038.html'
  - url: 'http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert'
tags:
  - osv
  - pip
epss: 0.02968
epssPercentile: 0.86583
ingestedAt: '2026-07-08T18:25:50.583Z'
---

## Overview

The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.

## Affected packages

- `zope <= 2.2`

## Remediation

Refer to the advisory for the patched release.
