Plone CMS Incorrect Permission Assignment for Critical Resource Vulnerability - CVE-2021-33509 - Vulnerability Database

Plone CMS Incorrect Permission Assignment for Critical Resource Vulnerability - CVE-2021-33509

Critical
Reference: CVE-2021-33509
Title: Plone CMS Incorrect Permission Assignment for Critical Resource Vulnerability
Overview:

Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.