Plone v6.0.9 vulnerability allows remote attackers to view and list all files
CVE-2024-22889
7.5HIGH
What is CVE-2024-22889?
An access control vulnerability exists in Plone version v6.0.9 that allows remote attackers to exploit the system by sending specially crafted requests. This flaw enables unauthorized individuals to view and list all files hosted on the affected website, leading to potential unauthorized access to sensitive information. Organizations utilizing this version of Plone should assess their systems and implement appropriate security measures to mitigate this risk.
