Looking for the vulnerability index of Invicti's legacy products?
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4196) - Vulnerability Database

Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4196)

Description

The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request.

References

Related Vulnerabilities