CVE-2016-4043

Description

Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.

Risk Information

Base Score
4.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.139

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-4043 are affected in Python-plone 5.0.4Windows
Vulnerabilities CVE-2016-4041,CVE-2016-4043 are affected in Python-plone 5.1a1Windows
Vulnerabilities CVE-2016-4043 are affected in Python-plone for linux 5.0.4Linux
Vulnerabilities CVE-2016-4041,CVE-2016-4043 are affected in Python-plone for linux 5.1a1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234