// For flags

CVE-2011-4030

 

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

El componente CMFEditions v2.x en Plone v4.0.x hasta v4.0.9, v4.1, y v4.2 hasta v4.2a2 no previene clases KwAsAttributes publicables, lo que permite a atacantes remotos acceder a sub-objetos a través de vectores no especificados, una vulnerabilidad diferente que CVE-2011-3587.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-10-09 CVE Reserved
  • 2011-10-10 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0a1
Search vendor "Plone" for product "Cmfeditions" and version "2.0a1"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b1
Search vendor "Plone" for product "Cmfeditions" and version "2.0b1"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b2
Search vendor "Plone" for product "Cmfeditions" and version "2.0b2"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b3
Search vendor "Plone" for product "Cmfeditions" and version "2.0b3"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b4
Search vendor "Plone" for product "Cmfeditions" and version "2.0b4"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b5
Search vendor "Plone" for product "Cmfeditions" and version "2.0b5"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b6
Search vendor "Plone" for product "Cmfeditions" and version "2.0b6"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b7
Search vendor "Plone" for product "Cmfeditions" and version "2.0b7"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b8
Search vendor "Plone" for product "Cmfeditions" and version "2.0b8"
-
Affected
Plone
Search vendor "Plone"
Cmfeditions
Search vendor "Plone" for product "Cmfeditions"
2.0b9
Search vendor "Plone" for product "Cmfeditions" and version "2.0b9"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0
Search vendor "Plone" for product "Plone" and version "4.0"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.1
Search vendor "Plone" for product "Plone" and version "4.0.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.2
Search vendor "Plone" for product "Plone" and version "4.0.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.3
Search vendor "Plone" for product "Plone" and version "4.0.3"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.4
Search vendor "Plone" for product "Plone" and version "4.0.4"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.5
Search vendor "Plone" for product "Plone" and version "4.0.5"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.6.1
Search vendor "Plone" for product "Plone" and version "4.0.6.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.7
Search vendor "Plone" for product "Plone" and version "4.0.7"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.8
Search vendor "Plone" for product "Plone" and version "4.0.8"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.0.9
Search vendor "Plone" for product "Plone" and version "4.0.9"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.1
Search vendor "Plone" for product "Plone" and version "4.1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2
Search vendor "Plone" for product "Plone" and version "4.2"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2a1
Search vendor "Plone" for product "Plone" and version "4.2a1"
-
Affected
Plone
Search vendor "Plone"
Plone
Search vendor "Plone" for product "Plone"
4.2a2
Search vendor "Plone" for product "Plone" and version "4.2a2"
-
Affected