CVE-2008-0164: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the joinform page and (2) change the privileges of arbitrary groups via the prefsgroupsoverview page.
Other sources
Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS before 3.1 allow remote attackers to (1) add arbitrary accounts via the joinform page and (2) change the privileges of arbitrary groups via the prefsgroupsoverview page.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0164?
CVE-2008-0164 is classified as a high severity vulnerability due to its potential for unauthorized account creation and privilege escalation.
How do I fix CVE-2008-0164?
To resolve CVE-2008-0164, upgrade Plone CMS to version 3.1 or later.
What types of attacks are associated with CVE-2008-0164?
CVE-2008-0164 is associated with cross-site request forgery (CSRF) attacks, allowing remote attackers to exploit the vulnerability.
Which versions of Plone CMS are affected by CVE-2008-0164?
CVE-2008-0164 affects Plone CMS versions 3.0.5 and 3.0.6.
Can CVE-2008-0164 lead to unauthorized access?
Yes, CVE-2008-0164 can lead to unauthorized account creation and modification of group privileges.