Description
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Database Reset Multiple Security Bypass Vulnerabilities (3.1)
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.16.68)
WordPress Plugin Newsletters Unspecified Vulnerability (4.5.5.2)
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-5954)