CVE-2012-5487

Description

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

Risk Information

Base Score
9.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.788

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Python-plone 4.2.3Windows
Multiple vulnerabilities are fixed in Python-plone 4.3b1Windows
Multiple vulnerabilities are fixed in Python-plone for linux 4.2.3Linux
Multiple vulnerabilities are fixed in Python-plone for linux 4.3b1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234