CVE-2011-4924

Description

Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.99

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2011-4924 are fixed in Python-zope2 2.12.22Windows
Vulnerabilities CVE-2011-4924 are fixed in Python-zope2 2.13.12Windows
Vulnerabilities CVE-2011-4924 are fixed in Python-zope2 for linux 2.12.22Linux
Vulnerabilities CVE-2011-4924 are fixed in Python-zope2 for linux 2.13.12Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234