9.3

CVE-2011-4030

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

Data is provided by the National Vulnerability Database (NVD)
PloneCmfeditions Version2.0a1
PloneCmfeditions Version2.0b1
PloneCmfeditions Version2.0b2
PloneCmfeditions Version2.0b3
PloneCmfeditions Version2.0b4
PloneCmfeditions Version2.0b5
PloneCmfeditions Version2.0b6
PloneCmfeditions Version2.0b7
PloneCmfeditions Version2.0b8
PloneCmfeditions Version2.0b9
PlonePlone Version4.0
PlonePlone Version4.0.1
PlonePlone Version4.0.2
PlonePlone Version4.0.3
PlonePlone Version4.0.4
PlonePlone Version4.0.5
PlonePlone Version4.0.6.1
PlonePlone Version4.0.7
PlonePlone Version4.0.8
PlonePlone Version4.0.9
PlonePlone Version4.1
PlonePlone Version4.2
PlonePlone Version4.2a1
PlonePlone Version4.2a2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.07% 0.757
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C