Safety vulnerability ID: 67964
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.
Latest version: 6.1.1
The Plone Content Management System
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application