PYSEC-2026-2888
Dashboard / Vulnerabilities / PYSEC-2026-2888
PYSEC-2026-2888
Summary: Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
Details: plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exploited in the wild in June 2011.
References: https://nvd.nist.gov/vuln/detail/CVE-2011-1950, https://exchange.xforce.ibmcloud.com/vulnerabilities/67695, https://github.com/advisories/GHSA-2qx8-589j-gcpx, https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-16.yaml, http://plone.org/products/plone/security/advisories/CVE-2011-1950, https://pypi.org/project/plone-app-users
Affected packages
Package
Name: plone-app-users
Purl: pkg:pypi/plone-app-users
Affected ranges
Type: ECOSYSTEM
Events:
