Description
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
Remediation
References
Related Vulnerabilities
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-4042)
Oracle Database Server CVE-2019-2547 Vulnerability (CVE-2019-2547)
OpenSSL CVE-2023-5363 Vulnerability (CVE-2023-5363)
Magento Insufficient Verification of Data Authenticity Vulnerability (CVE-2019-8112)