Description
The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458.
Remediation
References
Related Vulnerabilities
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-42029)
WordPress Plugin Quick Event Manager Security Bypass (9.2.16)
WordPress Plugin Locations Cross-Site Request Forgery (3.2.1)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-9933)
WordPress Plugin WP CleanFix Cross-Site Request Forgery (2.4.4)