Description
at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin MailPoet Newsletters (Previous) SQL Injection (2.2)
OpenSSL Resource Management Errors Vulnerability (CVE-2011-3210)
Caddy Web Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29718)
WordPress Plugin GorillaForms-Custom Contact Forms Unspecified Vulnerability (2.0.3)