HIGH 7.3 PyPI
Plone vulnerable to privilege escalation in WebDAV
GHSA-qqgj-22gr-73vx · CVE-2016-4041 · PYSEC-2017-55
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2016-4041
- PACKAGE https://github.com/plone/Plone
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2017-55.yaml
- WEB https://plone.org/security/hotfix/20160419/privilege-escalation-in-webdav
- WEB http://www.openwall.com/lists/oss-security/2016/04/20/1
Ready to move
Start Securing
Free, no credit card | First findings in minutes