Description
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Python script.
Remediation
References
Related Vulnerabilities
OpenSSL Missing Cryptographic Step Vulnerability (CVE-2025-69418)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0702)
Sqlite Other Vulnerability (CVE-2019-20218)
MySQL Other Vulnerability (CVE-2004-0837)
Nginx Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2025-1695)