Vulnerability Details CVE-2016-4043
Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.7%
CVSS Severity
CVSS v3 Score 4.9
CVSS v2 Score 3.5
Products affected by CVE-2016-4043
-
cpe:2.3:a:plone:plone:5.0
-
cpe:2.3:a:plone:plone:5.0.1
-
cpe:2.3:a:plone:plone:5.0.2
-
cpe:2.3:a:plone:plone:5.0.3
-
cpe:2.3:a:plone:plone:5.0.4
-
cpe:2.3:a:plone:plone:5.1a1