Zope allows attackers to modify raw image and file data
Moderate severity
GitHub Reviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Description
Published by the National Vulnerability Database
Dec 18, 2000
Published to the GitHub Advisory Database
Apr 30, 2022
Reviewed
Sep 18, 2023
Last updated
Sep 18, 2023
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.
References