9.3
CVE-2011-4030
- EPSS 1.07%
- Published 10.10.2011 10:55:06
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.
Data is provided by the National Vulnerability Database (NVD)
Plone ≫ Cmfeditions Version2.0a1
Plone ≫ Cmfeditions Version2.0b1
Plone ≫ Cmfeditions Version2.0b2
Plone ≫ Cmfeditions Version2.0b3
Plone ≫ Cmfeditions Version2.0b4
Plone ≫ Cmfeditions Version2.0b5
Plone ≫ Cmfeditions Version2.0b6
Plone ≫ Cmfeditions Version2.0b7
Plone ≫ Cmfeditions Version2.0b8
Plone ≫ Cmfeditions Version2.0b9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.07% | 0.757 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|