Description
typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.
Remediation
References
Related Vulnerabilities
XWiki CVE-2022-31166 Vulnerability (CVE-2022-31166)
WordPress Plugin Salon Booking System Multiple Information Disclosure Vulnerabilities (7.6.2)
WordPress Plugin Ad Blocker Notify Lite Cross-Site Scripting (2.4.0)
WordPress Plugin WP Users Exporter CSV Injection (1.4.2)
WordPress Plugin MAC PHOTO GALLERY Multiple Security Bypass Vulnerabilities (3.0)