Description
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.
Remediation
References
Related Vulnerabilities
Undertow Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-3859)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-0813)
WordPress Plugin Photoracer Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (1.0)
WordPress Plugin YITH WooCommerce Gift Cards Security Bypass (1.3.7)