Description
Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.
Remediation
References
Related Vulnerabilities
WordPress Plugin WishList Member X Remote Code Execution (3.25.1)
WordPress Plugin WP-PostRatings Cross-Site Scripting (1.50)
WordPress Plugin Age Gate Unspecified Vulnerability (2.18.5)
SharePoint CVE-2021-28478 Vulnerability (CVE-2021-28478)
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2020-1439)