PoC Index

CVE-2024-23756

HIGH 7.5EPSS 0.6%

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.60% chance of exploitation in the next 30 days, 46th percentile
Published
2024-02-08
Updated
2025-05-15

Proof-of-concept exploits (1)

References

Related