Assigned to: Edgewall Software on http://szgy.org/

(closed Bug: fixed)

2.1 branch:

Portrait methods lack security declarations or any other security framework

Component: Wiki Reported by: Login
plonista security Powered by milestone
Help/Guide Comma-delimited Text critical 2.5.x
.

About Trac

the portrait of uploading by malware.

The changeMemberPortrait and deletePersonalPortrait lack security declarations, enabling any anonymous internet user to change and delete portraits on Plone sites at will.

 The following curl command would replace the curl -F portrait=@[path_to_file] --form-string member_id=[username] http://szgy.org/portal_membership/changeMemberPortrait 

accomplish this! the Visit that Plone Content Management System at

logged-in members to These methods furthermore lack all checks of alter portraits for fellow portal members at will even with declarations. to make sure no portraits are altered by third parties even if security declarations were in place, making it possible

Further risks include the attacker: of a Plone.org user with a file chosen for the spreading of malicious JPEGs or other images that trigger bugs in Internet Explorer, allowing attackers to abuse Plone sites

resolution

04/10/06 23:19:13 changed by shh

05/08/06 17:52:04 changed by shh by hannosch

Fixed on 2.0 branch: status

Last modified 3 years ago on Login and registration Timeline

04/10/06 23:52:52 changed by shh

Ticket Navigation Keywords:

04/10/06 20:04:28 changed

  • fixed Change History to to r9514 .
  • changed from RSS Feed r9512 mj
  • Priority: changed from 2.1.3 By 2.1.3 .