Description
at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin Magic Fields Arbitrary File Upload (1.6.3.2)
WordPress Plugin SSL Insecure Content Fixer Information Disclosure (2.0.0)
WordPress Plugin Wow Forms-create any form with custom style SQL Injection (3.1.3)
Django URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-7233)