Exploitation Summary
CVE-2011-1950 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
Description
plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exploited in the wild in June 2011.
References (7)
Core 7
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/44775
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/48005
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67695
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/72729
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/8269
Patch, Vendor Advisory x_refsource_confirm
http://plone.org/products/plone/security/advisories/CVE-2011-1950
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/518155/100/0/threaded
Scores
EPSS
0.0158
EPSS Percentile
72.9%
Details
VulnCheck KEV
2011-06-06
InTheWild.io
2018-10-09
CWE
CWE-264
Status
published
Products (4)
plone/plone
4.0
plone/plone
4.1
pypi/Plone
4.0.1 - 4.0.6PyPI
pypi/plone.app.users
1.0a1 - 1.0.5PyPI
Published
Jun 06, 2011
Tracked Since
Feb 18, 2026