CVE-2011-2528

Zope <2.12.19,2.13.8 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.

References (8)

Core 8
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45056
Patch, Vendor Advisory x_refsource_confirm
http://plone.org/products/plone/security/advisories/20110622
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/12/9
Patch, Vendor Advisory x_refsource_confirm
http://plone.org/products/plone-hotfix/releases/20110622
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45111
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/04/6

Scores

EPSS 0.0201
EPSS Percentile 78.9%

Details

Status published
Products (42)
plone/plone 3.0
plone/plone 3.0.1
plone/plone 3.0.2
plone/plone 3.0.3
plone/plone 3.0.4
plone/plone 3.0.5
plone/plone 3.0.6
plone/plone 3.1
plone/plone 3.1.1
plone/plone 3.1.2
... and 32 more
Published Jul 19, 2011
Tracked Since Feb 18, 2026