CVE-2009-0662Medium▾ SunlitModerate severity vulnerability that affects Products.PlonePAS
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
1.0% → 1.0%
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
products-plonepas >= 3, < 3.9Upgrade to a patched release:
products-plonepas 3.9