CVE-2011-1950

High PUBLISHED

plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as...

Plone · Plone

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
5.5 Medium

At a Glance

plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exploited in the wild in June 2011.

CVE Published
Jun 06, 2011
Exploitation Reported
Jun 06, 2011
CVSS
5.5 Medium
EPSS
Remote Low complexity

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 44775 secunia.com · Third-Party Advisory http://secunia.com/advisories/44775
  • 8269 securityreason.com · Third-Party Advisory http://securityreason.com/securityalert/8269
  • 48005 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/48005
  • plone-data-security-bypass(67695) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/67695
  • 72729 osvdb.org · VDB Entry http://osvdb.org/72729
Show 2 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.