7.2
CVSSv2

CVE-2000-0725

Published: 20/10/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Zope prior to 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.

Vulnerable Product Search on Vulmon Subscribe to Product

zope zope 2.1.1

zope zope 2.1.7

zope zope 2.2_beta1

zope zope 1.10.3