CVE-2006-1711: Medium severity Plone plone vulnerability
Published Apr 11, 2006
·Updated
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.
Affected Software
6 affected componentsFixes available
pip/plone=2.5-beta1
pip/plone>=2.1.0<=2.1.2
pip/plone<=2.0.5
2.0.6
Plone plone=2.0.5
Plone plone=2.1.2
Plone plone=2.5_beta1
Event History
Apr 11, 2006
CVE Published
via NVD·06:06 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 1, 2022
Advisory Published
via GitHub·06:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2006-1711?
CVE-2006-1711 is considered a medium severity vulnerability due to its potential to allow unauthorized modification of user portraits.
2
How do I fix CVE-2006-1711?
To fix CVE-2006-1711, upgrade Plone to version 2.0.6 or later.
3
Which Plone versions are affected by CVE-2006-1711?
CVE-2006-1711 affects Plone versions 2.0.5, 2.1.2, and 2.5-beta1.
4
What can attackers do if CVE-2006-1711 is exploited?
If CVE-2006-1711 is exploited, attackers can modify user portraits and potentially compromise user accounts.
5
Is CVE-2006-1711 related to user account security in Plone?
Yes, CVE-2006-1711 poses a risk to user account security by allowing unauthorized alterations to personal user data.