Recommended Hotfix out for Plone 2.5.x
Plone releases that include PlonePAS (Plone 2.5.*) include a vulnerability that allows a user to masquerade as a group. HSR recommends this Hotfix for all Plone 2.5.x installs that allow anonymous user registration. Please file a ticket to have us install it for you. More information: PlonePAS user/group fix (CVE-2006-4249).