CVE-2024-23756
Plone 5.2.13
Public PoC
Published
08 February 2024
Modified
17 June 2026
CVSS Score v3.1
7.5
Click a component to see what it means
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.0060
46th percentile
Summary
CVE-2024-23756 is a high-severity an unspecified weakness vulnerability in Plone Plone. Its CVSS base score is 7.5 (High).
Operationally, ranked at the 46th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-21209
Vulnerability Data
The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.
- CWE(s)
Related Threats
CVEs Like This One
CVE-2024-0669Same product: Plone Plone
CVE-2024-22889Same product: Plone Plone
CVE-2023-41048Same product: Plone Plone
CVE-2024-23054Same vendor: Plone
CVE-2023-42457Same vendor: Plone
CVE-2026-28413Same vendor: Plone
CVE-2024-23055Same vendor: Plone
Affected Assets
plone
plone
5.2.13
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.