|
The issue involves the fmt attribute of dtml-var tags.Without this correction, Zope does not check security access to methodsinvoked through fmt. This issue could allow partially trusted users withenough knowledge of Zope to call, in a limited way, methods they would nototherwise be allowed to access. |