Description
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.
Remediation
References
Related Vulnerabilities
Jenkins Incorrect Authorization Vulnerability (CVE-2017-2599)
WordPress Plugin WP-Stats-Dashboard Multiple Cross-Site Scripting Vulnerabilities (2.6.5.1)
Joomla Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-15697)
WordPress Plugin Catch Breadcrumb Security Bypass (1.6)
WordPress Plugin Efence Multiple Cross-Site Scripting Vulnerabilities (1.3.2)