Red Hat Bugzilla – Bug 1264791
CVE-2015-7315 plone: Unauthorized user creation
Last modified: 2016-01-22 08:46:20 EST
A vulnerability that allows remote attackers to add a new member to a Plone site when registration is enabled, without acknowledgment of site administrator was found. Versions affected are Plone 3.x, 4.1.x, 4.2.x, <4.3.7, <5.0rc1. Upstream patch: https://github.com/zopefoundation/Products.CMFCore/commit/e1d981bfa14b664317285f0f36498f4be4a23406 CVE request: http://seclists.org/oss-sec/2015/q3/586