---
id: CVE-2006-4247
aliases:
  - GHSA-5hch-v5pq-x4qp
  - PYSEC-2006-5
title: >-
  Plone allows anonymous users to reset any users password through the web via
  Password Reset Tool
summary: >-
  Plone allows anonymous users to reset any users password through the web via
  Password Reset Tool
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
vendor: plone
product: plone
ecosystem: pip
affected:
  - 'plone >= 2.5, < 2.5.1'
patched:
  - plone 2.5.1
published: '2022-05-01'
updated: '2026-07-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-5hch-v5pq-x4qp'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2006-4247'
  - url: 'https://github.com/plone/Plone'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2006-5.yaml
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2006-9.yaml
  - url: 'http://plone.org/about/security/advisories/cve-2006-4247'
tags:
  - osv
  - pip
epss: 0.01012
epssPercentile: 0.61193
ingestedAt: '2026-07-09T18:56:35.184Z'
---

## Overview

Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of other users, related to "an erroneous security declaration."

## Affected packages

- `plone >= 2.5, < 2.5.1`

## Remediation

Upgrade to a patched release:

- `plone 2.5.1`
