plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exploited in the wild in June 2011.
"https://github.com/pypa/advisory-database/blob/main/vulns/plone/PYSEC-2011-16.yaml"