CVE-2013-4197: Input Validation
A security flaw (privilege defined with unsafe actions) was found in the way portrait handling component of Plone, a user friendly and powerful content management system, performed portraits management. Remote attacker, authenticated Plone user could use this flaw to modify or delete portraits of other users.
Other sources
memberportrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4197?
CVE-2013-4197 has a medium severity rating as it allows authenticated users to manipulate portraits contrary to intended permissions.
How do I fix CVE-2013-4197?
To resolve CVE-2013-4197, upgrade your Plone installation to version 4.3.2, 4.2.6, or 4.1.1.
Who is affected by CVE-2013-4197?
Authenticated users of Plone versions prior to patch 4.3.2, 4.2.6, or 4.1.1 are at risk from CVE-2013-4197.
What kind of actions can be exploited in CVE-2013-4197?
CVE-2013-4197 allows authenticated users to modify or delete portraits within the Plone CMS.
Is there any workaround available for CVE-2013-4197?
There are no known workarounds for CVE-2013-4197, so updating to a patched version is necessary.