CVE-2012-5489

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT

Description

The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

The core of the Plone content management system
GitHubGitHub
307