Description
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.
Remediation
References
Related Vulnerabilities
Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35543)
WordPress Plugin Simple Sitemap-Create a Responsive HTML Sitemap Cross-Site Scripting (3.5.7)
WordPress Plugin Advanced Access Manager Unspecified Vulnerability (5.9.8.1)