Looking for the vulnerability index of Invicti's legacy products?
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4198) - Vulnerability Database

Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4198)

Description

mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.

References

Related Vulnerabilities