Description
uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-40316)
IBM WebSEAL Missing Authorization Vulnerability (CVE-2020-4499)
WordPress Plugin ImageLinks Interactive Image Builder for WordPress Cross-Site Scripting (1.5.2)
WordPress Plugin Contact Form 7 International Sms Integration Cross-Site Scripting (1.2)