CVE-2015-7317: Medium severity kupu project vulnerability
An incorrect security declaration would allow any authenticated user to edit kupu settings--the wysiwyg editor for old versions of Plone. Versions affected are all versions Plone 3 through 4.2.
Upstream hotfix:
https://plone.org/security/20150910/
CVE request:
http://seclists.org/oss-sec/2015/q3/588
Other sources
Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7317?
The severity of CVE-2015-7317 is categorized as high due to the ability for any authenticated user to edit critical settings.
How do I fix CVE-2015-7317?
To fix CVE-2015-7317, apply the upstream hotfix provided by Plone for affected versions.
Which versions are affected by CVE-2015-7317?
CVE-2015-7317 affects all versions of Plone from 3 through 4.2, including Kupu versions up to 1.4.16.
Can unauthenticated users exploit CVE-2015-7317?
No, only authenticated users can exploit CVE-2015-7317 to make unauthorized changes.
What is the impact of CVE-2015-7317 on Plone installations?
The impact of CVE-2015-7317 allows users to modify editor settings which could lead to further security vulnerabilities.