Description
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
Remediation
References
Related Vulnerabilities
Oracle JRE Incorrect Conversion between Numeric Types Vulnerability (CVE-2022-34169)
MySQL CVE-2022-21319 Vulnerability (CVE-2022-21319)
WordPress Plugin Timed Popup Cross-Site Request Forgery (1.3)
WordPress Plugin Candidate Application Form Arbitrary File Disclosure (1.6)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-12466)