Description
z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.
Remediation
References
Related Vulnerabilities
WordPress Plugin Baggage Freight Shipping Australia Arbitrary File Upload (0.1.0)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1240)
WebLogic CVE-2023-22040 Vulnerability (CVE-2023-22040)
WordPress Plugin Persian Woocommerce SMS Cross-Site Scripting (3.3.2)