Total vulnerabilities in the database
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
Software | From | Fixed in |
---|---|---|
zope / zope | 2.4.0 | 2.4.0.x |
zope / zope | 2.5.1 | 2.5.1.x |