Safety vulnerability ID: 36898
The information on this page was manually curated by our Cybersecurity Intelligence Team.
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission. See: CVE-2020-7941.
Latest version: 6.1.1
The Plone Content Management System
------------------
- create a TinyMCE template for Board meeting minutes
[cdw9]
- temporarily remove releasesecurityinfo until we can deal with existing
content types by the same name on the live site
[tkimnguyen]
- merge GSoC 2017 work! ploneorg.addonlisting and ploneorg.releasesecurityinfo
[pavithirakc, loechel, tkimnguyen]
- add uwosh.pfg.d2c
[tkimnguyen]
- change sponsors page to display sponsor logos based on FoundationSponsor object queries
[tkimnguyen]
- change home page to display premium sponsor logos taken from new
FoundationSponsor objects instead of the logo images
[tkimnguyen]
- make some Sponsor fields optional, remove Ammado payment method
[tkimnguyen]
- new Foundation Sponsor content type, workflow, role, permissions, view
[tkimnguyen]
- Allow viewing of Foundation Member merit if have View Details permission
[tkimnguyen]
- Fix workflow for members to make renewal easier, and hook
up broken transitions
[cdw9]
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application