Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
{
"github_reviewed_at": "2024-03-06T15:31:16Z",
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2024-03-06T00:15:52Z",
"cwe_ids": [
"CWE-276"
]
}