CVE-2011-4030

Description

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
1.098

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Python-plone 4.1.1Windows
Vulnerabilities CVE-2011-4030 are fixed in Python-plone 4.0.10Windows
Vulnerabilities CVE-2011-4030 are fixed in Python-plone 4.2a3Windows
Multiple vulnerabilities are fixed in Python-plone for linux 4.1.1Linux
Vulnerabilities CVE-2011-4030 are fixed in Python-plone for linux 4.0.10Linux
Vulnerabilities CVE-2011-4030 are fixed in Python-plone for linux 4.2a3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234