Description
mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.
Remediation
References
Related Vulnerabilities
WordPress Plugin ThemeGrill Demo Importer Security Bypass (1.6.1)
WordPress Plugin JoomSport-for Sports: Team & League, Football, Hockey & more SQL Injection (3.3)
SugarCRM Other Vulnerability (CVE-2009-2146)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2011-2719)
IBM WebSEAL Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-4699)