← Back

CVE-2011-4030

nvd nist
Published: Oct 10, 2011Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

Affected (24)

Products: Plone: Cmfeditions, Plone
2 products
Cmfeditions
Plone
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Plone
Version 2.0a1
Version 2.0b1
Version 2.0b2
Version 2.0b3
Version 2.0b4
Version 2.0b5
Version 2.0b6
Version 2.0b7
Version 2.0b8
Version 2.0b9
Plone
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6.1
Version 4.0.7
Version 4.0.8
Version 4.0.9
Version 4.0
Version 4.1
Version 4.2
Version 4.2a1
Version 4.2a2

Related CWEs

References (10)

Timeline

No history available yet.