Description
Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.
Remediation
References
Related Vulnerabilities
WordPress Plugin Keyword Meta Cross-Site Request Forgery (3.0)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-2196)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-8563)
WordPress Plugin Easy2Map Multiple SQL Injection Vulnerabilities (1.2.4)
Nexus Repository Manager Incorrect Authorization Vulnerability (CVE-2018-16620)