VulnerabilityModified
CVE-2015-7315
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.
MEDIUM 5.9EPSS 2.02%
Does this matter?
Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.
Description
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- plone/plone
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2015/09/22/13Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1264791Issue Tracking, Patch, Third Party Advisory
- https://github.com/zopefoundation/Products.CMFCore/commit/e1d981bfa14b664317285f0f36498f4be4a23406Issue Tracking, Patch, Third Party Advisory
- https://plone.org/security/hotfix/20150910/anonymous-is-able-to-create-plone-membersVendor Advisory
- http://www.openwall.com/lists/oss-security/2015/09/22/13Mailing List, Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1264791Issue Tracking, Patch, Third Party Advisory
- https://github.com/zopefoundation/Products.CMFCore/commit/e1d981bfa14b664317285f0f36498f4be4a23406Issue Tracking, Patch, Third Party Advisory
- https://plone.org/security/hotfix/20150910/anonymous-is-able-to-create-plone-membersVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.