Description
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.
Remediation
References
Related Vulnerabilities
WordPress Plugin ContentStudio Multiple Vulnerabilities (1.2.5)
WordPress Plugin Advanced Database Cleaner SQL Injection (3.0.1)
WordPress Plugin Gallery-Video Gallery and Youtube Gallery Cross-Site Scripting (1.7.01)
WebLogic CVE-2018-15756 Vulnerability (CVE-2018-15756)
WordPress Plugin Product Catalog for WordPress Unspecified Vulnerability (1.4.5)