CVE-2009-0662

unknown
Published 2018-07-23 · Modified 2026-05-21
CVSS v3
CVSS v2
VIR risk

Description

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
python PyPIproducts-plonepas>=3,<3.93.9
python PyPIplone>=3.0,<=3.5

References

Verify integrity in audit chain (admin only). AS-IS.