Executive brief
PlonePAS, a component used by the Plone content management system to handle user authentication and permissions, contains a flaw in its login form processing. This vulnerability allows a user who is already logged into the system to impersonate any other user. An attacker could use this to gain unauthorized access to sensitive data or administrative functions by assuming the identity of a high-privileged account.
Technical details
A vulnerability in Products.PlonePAS (versions 3.x before 3.9 and 3.2.x before 3.2.2) stems from improper handling of the login form. The flaw is categorized as CWE-287 (Improper Authentication). A remote authenticated attacker can exploit this by using unspecified vectors to acquire the identity of an arbitrary user. This effectively allows for privilege escalation or account takeover within the Plone environment. The issue is resolved in version 3.9.
Affected products
- Plone Products.PlonePAS 3.x before 3.9, 3.2.x before 3.2.2
Timeline
- 2009-04-23: disclosed
- 2009-04-23: advisory: NVD published date
- 2018-07-23: other: GitHub Advisory published