CVE-2012-5493: Code Injection
gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.
Other sources
gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5493?
CVE-2012-5493 is considered a medium severity vulnerability due to its capability of allowing remote authenticated users to bypass the Python sandbox.
How do I fix CVE-2012-5493?
To fix CVE-2012-5493, upgrade to Plone version 4.2.3 or 4.3-beta1 or later.
What versions of Plone are affected by CVE-2012-5493?
CVE-2012-5493 affects Plone versions before 4.2.3 and all versions of 4.3 prior to beta 1.
Who can exploit CVE-2012-5493?
CVE-2012-5493 can be exploited by remote authenticated users with specific permissions.
What type of vulnerability is CVE-2012-5493?
CVE-2012-5493 is a remote code execution vulnerability that allows the execution of arbitrary Python code.