Permissions, Privileges, and Access Controls in Plone - CVE-2012-5487
Published: September 30, 2014 / Updated: August 10, 2020
Plone
Detailed vulnerability description
The vulnerability allows a remote #AU# to execute arbitrary code.
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.