CVE-2012-5491: Plone
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.
Affected products
- Plone Plone: up to and including 4.2.2; version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; …
Published 2014-09-30. Last modified 2026-06-16.