GHSA-4j3w-g62x-hrcpHighCVSS 7.5

Plone Cross-site request forgery (CSRF)

Published
May 1, 2022
Last Modified
June 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS before 3.1 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.

🎯 Affected products1

  • pip/Plone:< 3.1

🔗 References (11)