VDB
KO
MEDIUM

GHSA-j5cc-3h6r-jqh4

Zope DocumentTemplate package allows unauthenticated write

Details

The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / zope
Introduced in: 0

No fixed version published yet for zope (pip). Pin to a known-safe version or switch to an alternative.

References