Looking for the vulnerability index of Invicti's legacy products?
Zope Web Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5489) - Vulnerability Database

Zope Web Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5489)

Description

The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

References

Related Vulnerabilities