An information exposure flaw was found in the way zip archives generation functionality of Plone, a user friendly and powerful content management system, enforced user access control privileges on the content to be included into the archive. A remote attacker could use this flaw to obtain sensitive information (by generating a zip archive from content they would not be otherwise able to access).
The CVE identifier of CVE-2013-4191 has been assigned to this issue:
Created plone tracking bugs for this issue:
Affects: epel-5 [bug 991015]