CVE-2024-23756
HIGHDescription
The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.
Is your site exposed to CVE-2024-23756?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| plone | plone |
References
Frequently Asked Questions
What is CVE-2024-23756? +
How severe is CVE-2024-23756? +
What products are affected by CVE-2024-23756? +
How do I check if I'm vulnerable to CVE-2024-23756? +
Related Vulnerabilities
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to …
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the …
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious …
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of …