CVE-2013-4198
EUVD-2014-008011.03.2014, 19:37
mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| plone | plone | 2.1 |
| plone | plone | 2.1.1 |
| plone | plone | 2.1.2 |
| plone | plone | 2.1.3 |
| plone | plone | 2.1.4 |
| plone | plone | 2.5 |
| plone | plone | 2.5.1 |
| plone | plone | 2.5.2 |
| plone | plone | 2.5.3 |
| plone | plone | 2.5.4 |
| plone | plone | 2.5.5 |
| plone | plone | 3.0 |
| plone | plone | 3.0.1 |
| plone | plone | 3.0.2 |
| plone | plone | 3.0.3 |
| plone | plone | 3.0.4 |
| plone | plone | 3.0.5 |
| plone | plone | 3.0.6 |
| plone | plone | 3.1 |
| plone | plone | 3.1.1 |
| plone | plone | 3.1.2 |
| plone | plone | 3.1.3 |
| plone | plone | 3.1.4 |
| plone | plone | 3.1.5.1 |
| plone | plone | 3.1.6 |
| plone | plone | 3.1.7 |
| plone | plone | 3.2 |
| plone | plone | 3.2.1 |
| plone | plone | 3.2.2 |
| plone | plone | 3.2.3 |
| plone | plone | 3.3 |
| plone | plone | 3.3.1 |
| plone | plone | 3.3.2 |
| plone | plone | 3.3.3 |
| plone | plone | 3.3.4 |
| plone | plone | 3.3.5 |
| plone | plone | 4.0 |
| plone | plone | 4.0.1 |
| plone | plone | 4.0.2 |
| plone | plone | 4.0.3 |
| plone | plone | 4.0.4 |
| plone | plone | 4.0.5 |
| plone | plone | 4.0.6.1 |
| plone | plone | 4.1 |
| plone | plone | 4.3 |
| plone | plone | 4.3.1 |
| plone | plone | 4.2 |
| plone | plone | 4.2.1 |
| plone | plone | 4.2.2 |
| plone | plone | 4.2.3 |
| plone | plone | 4.2.4 |
| plone | plone | 4.2.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References