CVE-2006-4247Critical· 9.1▾ MidnightPlone allows anonymous users to reset any users password through the web via Password Reset Tool
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
1.0% → 1.0%
Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of other users, related to "an erroneous security declaration."
plone >= 2.5, < 2.5.1Upgrade to a patched release:
plone 2.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2006-4249Medium· 5.9Plone allows a user to masquerade as a group
CVE-2008-0164High· 7.5Plone Cross-site request forgery (CSRF)
CVE-2024-22889Medium· 5.5Phone information disclosure vulnerability
CVE-2011-4030HighPlone anonymous access to sub-objects in CMFEditions where KwAsAttributes classes were publishable
CVE-2008-1394HighPlone CMS Improper Session Management
CVE-2006-1711MediumPlone allows remote users to modify arbitrary portraits