Junglewise Threat Intelligence

CVE-2006-4247: Plone Password Reset Tool unauthorized password reset

CVE-2006-4247 · Severity: critical · CVSS 9.1 · Published 2022-05-01

Vendors: PyPI.

Executive brief

A vulnerability in the Plone content management system allows unauthorized individuals to reset the passwords of any user on the site. By exploiting a flaw in the Password Reset Tool, an anonymous attacker can gain full control over user accounts, including administrative ones. This could lead to complete site takeover, data theft, or unauthorized content modification.

Technical details

An unspecified vulnerability exists in the Password Reset Tool (before version 0.4.1) within Plone 2.5 and 2.5.1 Release Candidate. The issue is rooted in an 'erroneous security declaration' that fails to properly restrict access to password reset functionality. A remote, unauthenticated attacker can exploit this flaw over the network to reset the passwords of arbitrary users. This allows for complete account takeover without any prior credentials or user interaction. The vulnerability is addressed in Plone version 2.5.1.

Affected products

  • Plone Foundation Plone >= 2.5, < 2.5.1

Timeline

  • 2006-09-29: disclosed: NVD published date
  • 2022-05-01: advisory: GitHub Advisory published

References

Related threats