Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.
2017-02-24T20:59:00.360
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.9 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | plone | plone | 5.0 | Yes |
Application | plone | plone | 5.0 | Yes |
Application | plone | plone | 5.0 | Yes |
Application | plone | plone | 5.0 | Yes |
Application | plone | plone | 5.0.1 | Yes |
Application | plone | plone | 5.0.2 | Yes |
Application | plone | plone | 5.0.3 | Yes |
Application | plone | plone | 5.0.4 | Yes |
Application | plone | plone | 5.1a1 | Yes |