CVE-2011-4924
MEDIUMZope 2.8.0-2.12.2, 3.1.1-3.4.1 - Cross-Site Scripting via Error Message Sanitization Bypass
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104
References (7)
Core 7
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2011-4924
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924
Third Party Advisory x_refsource_misc
https://access.redhat.com/security/cve/cve-2011-4924
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2012/01/19/19
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2012/01/19/16
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2012/01/19/17
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2012/01/19/18
Scores
CVSS v3
6.1
EPSS
0.0135
EPSS Percentile
68.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (3)
pypi/zope
3.1.1 - 3.7.3PyPI
pypi/zope2
0 - 2.12.22PyPI
zope/zope
2.8.0 - 2.8.12
Published
Nov 25, 2019
Tracked Since
Feb 18, 2026