ZeroHour

CVE-2024-23756

PoC
CVSS 3.1
7.5 high
EPSS
<1%p47
Published
()
Modified
Description

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

Vendors
plone
Products
plone
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.