Description
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.
Remediation
References
Related Vulnerabilities
WordPress Plugin arcResBookingWidget Multiple Vulnerabilities (1.0)
WordPress Plugin WordPress Portfolio and Gallery-GridKit Gallery Unspecified Vulnerability (1.8.18)
WordPress Plugin Booster for WooCommerce Multiple Vulnerabilities (5.6.6)
WordPress Plugin Frontend File Manager Cross-Site Request Forgery (21.3)