{"id":"GHSA-jcwh-rj6j-vm75","summary":"Plone allows remote users to modify arbitrary portraits","details":"Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.","aliases":["CVE-2006-1711","PYSEC-2026-733"],"modified":"2026-07-06T08:11:24.446878995Z","published":"2022-05-01T06:52:02Z","database_specific":{"github_reviewed_at":"2024-02-12T16:10:44Z","nvd_published_at":"2006-04-11T18:06:00Z","cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1711"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25781"},{"type":"PACKAGE","url":"https://github.com/plone/Plone"},{"type":"WEB","url":"https://web.archive.org/web/20060412111111/https://dev.plone.org/plone/ticket/5432"},{"type":"WEB","url":"https://web.archive.org/web/20060422195724/http://www.securityfocus.com/bid/17484"},{"type":"WEB","url":"http://www.debian.org/security/2006/dsa-1032"}],"affected":[{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.6"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jcwh-rj6j-vm75/GHSA-jcwh-rj6j-vm75.json"}},{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"last_affected":"2.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jcwh-rj6j-vm75/GHSA-jcwh-rj6j-vm75.json"}},{"package":{"name":"plone","ecosystem":"PyPI","purl":"pkg:pypi/plone"},"versions":["2.5-beta1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jcwh-rj6j-vm75/GHSA-jcwh-rj6j-vm75.json"}}],"schema_version":"1.9.0"}