---
id: CVE-2009-0662
aliases:
  - GHSA-pq3x-96c3-xgjg
  - PYSEC-2009-17
  - PYSEC-2026-739
title: Moderate severity vulnerability that affects Products.PlonePAS
summary: Moderate severity vulnerability that affects Products.PlonePAS
severity: medium
vendor: products-plonepas
product: products-plonepas
ecosystem: pip
affected:
  - 'products-plonepas >= 3, < 3.9'
patched:
  - products-plonepas 3.9
published: '2018-07-23'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pq3x-96c3-xgjg'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2009-0662'
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/50061'
  - url: 'https://github.com/advisories/GHSA-pq3x-96c3-xgjg'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2009-17.yaml
  - url: 'http://osvdb.org/53975'
  - url: 'http://plone.org/products/plone/security/advisories/cve-2009-0662'
  - url: 'http://secunia.com/advisories/34840'
  - url: 'http://www.securityfocus.com/bid/34664'
tags:
  - osv
  - pip
epss: 0.0097
epssPercentile: 0.60459
ingestedAt: '2026-07-08T18:25:51.818Z'
---

## Overview

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

## Affected packages

- `products-plonepas >= 3, < 3.9`

## Remediation

Upgrade to a patched release:

- `products-plonepas 3.9`
