CRITICAL 9.8 PyPI

Plone Unauthenticated Write Vulnerability

GHSA-w6g9-xccc-347h · CVE-2020-7941 · PYSEC-2020-90 · PYSEC-2026-459

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.

Ready to move

Start Securing

Free, no credit card | First findings in minutes