CVE-2011-1948
medium
CVSS v3
—
CVSS v2
4.3
VIR risk
4.3
Description
Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/44776
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/44775
Vendor advisory: secalert@redhat.com — http://plone.org/products/plone/security/advisories/CVE-2011-1948
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | products-passwordresettool | <2.0.6 | 2.0.6 |
| PyPI | products-cmfplone | <4.0.7 | 4.0.7 |
| PyPI | products-cmfplone | >=4.1a1,<4.1rc3 | 4.1rc3 |
| PyPI | plone | <4.1.1 | 4.1.1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| plone | plone | {"endIncluding":"4.1"} | |
| plone | plone | 1.0 | |
| plone | plone | 1.0.1 | |
| plone | plone | 1.0.2 | |
| plone | plone | 1.0.3 | |
| plone | plone | 1.0.4 | |
| plone | plone | 1.0.5 | |
| plone | plone | 1.0.6 | |
| plone | plone | 2.0 | |
| plone | plone | 2.0.1 | |
| plone | plone | 2.0.2 | |
| plone | plone | 2.0.3 | |
| plone | plone | 2.0.4 | |
| plone | plone | 2.0.5 | |
| plone | plone | 2.1 | |
| plone | plone | 2.1.1 | |
| plone | plone | 2.1.2 | |
| plone | plone | 2.1.3 | |
| plone | plone | 2.1.4 | |
| plone | plone | 2.5 | |
| plone | plone | 2.5.1 | |
| plone | plone | 2.5.2 | |
| plone | plone | 2.5.3 | |
| plone | plone | 2.5.4 | |
| plone | plone | 2.5.5 | |
| plone | plone | 3.0 | |
| plone | plone | 3.0.1 | |
| plone | plone | 3.0.2 | |
| plone | plone | 3.0.3 | |
| plone | plone | 3.0.4 | |
| plone | plone | 3.0.5 | |
| plone | plone | 3.0.6 | |
| plone | plone | 3.1 | |
| plone | plone | 3.1.1 | |
| plone | plone | 3.1.2 | |
| plone | plone | 3.1.3 | |
| plone | plone | 3.1.4 | |
| plone | plone | 3.1.5.1 | |
| plone | plone | 3.1.6 | |
| plone | plone | 3.1.7 | |
| plone | plone | 3.2 | |
| plone | plone | 3.2.1 | |
| plone | plone | 3.2.2 | |
| plone | plone | 3.2.3 | |
| plone | plone | 3.3 | |
| plone | plone | 3.3.1 | |
| plone | plone | 3.3.2 | |
| plone | plone | 3.3.3 | |
| plone | plone | 3.3.4 | |
| plone | plone | 3.3.5 | |
| plone | plone | 4.0 | |
| plone | plone | 4.0.1 | |
| plone | plone | 4.0.2 | |
| plone | plone | 4.0.3 | |
| plone | plone | 4.0.4 | |
| plone | plone | 4.0.5 | |
| plone | plone | 4.0.6.1 | |
References
- http://osvdb.org/72727
- http://plone.org/products/plone/security/advisories/CVE-2011-1948
- http://secunia.com/advisories/44775
- http://secunia.com/advisories/44776
- http://securityreason.com/securityalert/8269
- http://www.securityfocus.com/archive/1/518155/100/0/threaded
- http://www.securityfocus.com/bid/48005
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67693
- https://nvd.nist.gov/vuln/detail/CVE-2011-1948
- https://access.redhat.com/errata/RHSA-2012:0151
- https://access.redhat.com/security/cve/CVE-2011-1948
- https://bugzilla.redhat.com/show_bug.cgi?id=711494
- https://github.com/advisories/GHSA-p7h9-vf92-5fj5
- https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-14.yaml
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.