CVE-2011-1950

EXPLOITED IN THE WILD

Plone 4.0-4.1 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2011-1950 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exploited in the wild in June 2011.

References (7)

Core 7
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44775
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/48005
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67695
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/72729
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8269
Patch, Vendor Advisory x_refsource_confirm
http://plone.org/products/plone/security/advisories/CVE-2011-1950
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/518155/100/0/threaded

Scores

EPSS 0.0158
EPSS Percentile 72.9%

Details

VulnCheck KEV 2011-06-06
InTheWild.io 2018-10-09
CWE
CWE-264
Status published
Products (4)
plone/plone 4.0
plone/plone 4.1
pypi/Plone 4.0.1 - 4.0.6PyPI
pypi/plone.app.users 1.0a1 - 1.0.5PyPI
Published Jun 06, 2011
Tracked Since Feb 18, 2026