Vulnerability Details CVE-2011-4030
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.5%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2011-4030
-
cpe:2.3:a:plone:cmfeditions:2.0a1
-
cpe:2.3:a:plone:cmfeditions:2.0b1
-
cpe:2.3:a:plone:cmfeditions:2.0b2
-
cpe:2.3:a:plone:cmfeditions:2.0b3
-
cpe:2.3:a:plone:cmfeditions:2.0b4
-
cpe:2.3:a:plone:cmfeditions:2.0b5
-
cpe:2.3:a:plone:cmfeditions:2.0b6
-
cpe:2.3:a:plone:cmfeditions:2.0b7
-
cpe:2.3:a:plone:cmfeditions:2.0b8
-
cpe:2.3:a:plone:cmfeditions:2.0b9
-
cpe:2.3:a:plone:plone:4.0
-
cpe:2.3:a:plone:plone:4.0.1
-
cpe:2.3:a:plone:plone:4.0.2
-
cpe:2.3:a:plone:plone:4.0.3
-
cpe:2.3:a:plone:plone:4.0.4
-
cpe:2.3:a:plone:plone:4.0.5
-
cpe:2.3:a:plone:plone:4.0.6.1
-
cpe:2.3:a:plone:plone:4.0.7
-
cpe:2.3:a:plone:plone:4.0.8
-
cpe:2.3:a:plone:plone:4.0.9
-
cpe:2.3:a:plone:plone:4.1
-
cpe:2.3:a:plone:plone:4.2
-
cpe:2.3:a:plone:plone:4.2a1
-
cpe:2.3:a:plone:plone:4.2a2