MEDIUM 5.3 PyPI

Plone User account enumeration via crafted URL

GHSA-683w-84m7-p8pw · CVE-2012-5497 · PYSEC-2014-39

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.

Ready to move

Start Securing

Free, no credit card | First findings in minutes