提供了一个名为 的 Zope schema 风格字段类型,用于存储带有相关 MIME 类型的值。在 2.0.2、3.0.2 和 4.0.1 之前(视具体版本线而定),当 等于 时, 会直接返回未净化的已存储 值,包括那些声明为 输出类型的值。这种类型相等的快捷路径绕过了 转换,尽管该转换本身能够正确移除事件处理程序属性和不安全的 URI 协议。类型相等可能由配置了相同 和 的 字段引起,或者由 REST API 输入将 作为其内容类型提供所致。随后,原始存储值通过 无转义地输出,使得能够设置 字段的用户可以存储 J
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| plone | plone.app.textfield | < 2.0.2 |
affected |
>= 3.0.0, < 3.0.2 |
affected | ||
>= 4.0.0, < 4.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| plone | plone.app.textfield | < 2.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet