---
id: CVE-2000-1212
aliases:
  - GHSA-7whr-j8vf-r4wj
  - PYSEC-2026-756
title: Zope allows attackers to modify raw image and file data
summary: Zope allows attackers to modify raw image and file data
severity: medium
vendor: zope
product: zope
ecosystem: pip
affected:
  - 'zope >= 2.2.0, <= 2.2.4'
published: '2022-04-30'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7whr-j8vf-r4wj'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2000-1212'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/5778'
  - url: >-
      https://web.archive.org/web/20020117134418/http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000365
  - url: 'http://www.debian.org/security/2001/dsa-007'
  - url: 'http://www.redhat.com/support/errata/RHSA-2000-135.html'
  - url: 'http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert'
tags:
  - osv
  - pip
epss: 0.01542
epssPercentile: 0.73414
ingestedAt: '2026-07-08T18:25:47.242Z'
---

## Overview

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

## Affected packages

- `zope >= 2.2.0, <= 2.2.4`

## Remediation

Refer to the advisory for the patched release.
