CVE-2013-4198
MEDIUM4.3EPSS 0.30%Plone's authenticated users able to alter their password despite of policy definition
Published: 5/17/2022Modified: 10/18/2024
Description
`mail_password.py` in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.
Affected packages (2)
- PyPI/plone>= 2.1, <= 4.1
- PyPI/plone>= 2.1, < 4.1.1, >= 4.2, < 4.2.6, >= 4.3, < 4.3.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
References (8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2013-4198
- PATCHhttps://github.com/plone/Plone
- WEBhttp://plone.org/products/plone-hotfix/releases/20130618
- WEBhttp://plone.org/products/plone/security/advisories/20130618-announcement
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=978480
- WEBhttp://seclists.org/oss-sec/2013/q3/261
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2014-62.yaml
- WEBhttps://pypi.org/project/Products.PloneHotfix20130618