Description
Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.
Remediation
References
Related Vulnerabilities
WordPress 4.1.x PHP Object Injection (4.1 - 4.1.32)
WordPress Plugin Simplr Registration Form Plus+ Privilege Escalation (2.4.3)
Dot CMS Other Vulnerability (CVE-2016-4803)
Joomla! Core 1.7.x Cross-Site Scripting (1.7.0 - 1.7.2)
Atlassian Jira Missing Authentication for Critical Function Vulnerability (CVE-2019-8449)