CVE-2015-7315Medium· 5.9▾ SunlitPlone unauthorized member addition vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.0%
2.0% → 2.1%
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.
products-cmfplone >= 3.3.0, < 4.3.7products-cmfplone >= 5.0a1, < 5.0rc2plone >= 3.3, <= 3.3.6plone >= 4.0a1, <= 4.0.10plone >= 4.1a1, <= 4.1.6plone >= 4.2a1, <= 4.2.7plone >= 4.3a1, <= 4.3.6ploneUpgrade to a patched release:
products-cmfplone 4.3.7products-cmfplone 5.0rc2Connected by shared product, vendor, weakness, or advisory.