Description
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
Remediation
References
Related Vulnerabilities
WordPress Plugin BuddyPress Multiple Cross-Site Request Forgery Vulnerabilities (2.8.1)
WordPress Plugin Great Restaurant Menu WP SQL Injection (1.4.1)
WordPress Plugin WordPress Survey & Poll-Quiz, Survey and Poll Unspecified Vulnerability (1.5.8.5)
WordPress Plugin Startklar Elementor Addons Arbitrary File Deletion (1.7.13)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-15695)