4.9
CVSSv3

CVE-2016-4043

Published: 24/02/2017 Updated: 28/02/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Chameleon (five.pt) in Plone 5.0rc1 up to and including 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone 5.0

plone plone 5.0.2

plone plone 5.0.3

plone plone 5.0.4

plone plone 5.1a1

plone plone 5.0.1