Permissions, Privileges, and Access Controls in Plone - CVE-2013-4191
Published: March 11, 2014 / Updated: August 10, 2020
Plone
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in a zip archive, which allows remote attackers to obtain sensitive information by reading a generated archive.