First published: Mon Sep 21 2015(Updated: )
An incorrect security declaration would allow any authenticated user to edit kupu settings--the wysiwyg editor for old versions of Plone. Versions affected are all versions Plone 3 through 4.2. Upstream hotfix: <a href="https://plone.org/security/20150910/">https://plone.org/security/20150910/</a> CVE request: <a href="http://seclists.org/oss-sec/2015/q3/588">http://seclists.org/oss-sec/2015/q3/588</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Plone CMS | >=3<4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1264799 is considered high due to the exposure of sensitive settings to authenticated users.
To fix REDHAT-BUG-1264799, apply the upstream hotfix provided by Plone for affected versions.
REDHAT-BUG-1264799 affects all versions of Plone from version 3 through 4.2.
REDHAT-BUG-1264799 is a security misconfiguration vulnerability that allows unauthorized editing of settings.
Any authenticated user can exploit REDHAT-BUG-1264799 to edit the settings of the Kupu editor.