Skip to content

CVE-2013-4198

mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0031 (0.3%)
Percentil: 53.7%
EPSS: 2026-05-06

Afecta

plone:plone

Descripción técnica

mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.

Publicada: 11/3/2014, 19:37:02
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo