---
id: CVE-2006-4249
aliases:
  - GHSA-r7j4-82xw-8m9p
  - PYSEC-2006-6
title: Plone allows a user to masquerade as a group
summary: Plone allows a user to masquerade as a group
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
vendor: plone
product: plone
ecosystem: pip
affected:
  - 'plone >= 2.5, < 2.5.2'
patched:
  - plone 2.5.2
published: '2022-05-01'
updated: '2026-07-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-r7j4-82xw-8m9p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2006-4249'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/30762'
  - url: 'https://github.com/plone/Plone'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2006-10.yaml
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2006-6.yaml
  - url: 'http://plone.org/about/security/advisories/cve-2006-4249'
  - url: 'http://plone.org/products/plone-hotfix/releases/20061031'
  - url: 'http://secunia.com/advisories/23240'
  - url: 'http://www.securityfocus.com/bid/21460'
  - url: 'http://www.vupen.com/english/advisories/2006/4878'
tags:
  - osv
  - pip
epss: 0.01013
epssPercentile: 0.61746
ingestedAt: '2026-07-09T18:56:35.276Z'
---

## Overview

Unspecified vulnerability in PlonePAS in Plone 2.5 and 2.5.1, when anonymous member registration is enabled, allows an attacker to "masquerade as a group."

## Affected packages

- `plone >= 2.5, < 2.5.2`

## Remediation

Upgrade to a patched release:

- `plone 2.5.2`
