VYPR
High severity7.5NVD Advisory· Published Feb 8, 2024· Updated Jun 17, 2026

CVE-2024-23756

CVE-2024-23756

Description

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:plone:plone:5.2.13:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:plone:plone:5.2.13:*:*:*:*:*:*:*
    • (no CPE)range: =5.2.13 (5221)
  • Plone/Plone official Dockerdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.