CVE-2011-0720: Critical severity plone cms vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0720 to the following vulnerability:
Name: CVE-2011-0720 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0720 Assigned: 20110131 Reference: http://plone.org/products/plone/security/advisories/cve-2011-0720 Reference: http://www.securityfocus.com/bid/46102 Reference: http://secunia.com/advisories/43146 Reference: http://xforce.iss.net/xforce/xfdb/65099
Unspecified vulnerability in Plone 2.5 through 4.0 allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
The hotfix for this issue is available here: http://plone.org/products/plone-hotfix/releases/CVE-2011-0720/
Some Plone components are included in conga, so this flaw may have some impact there.
Other sources
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2011-0720?
CVE-2011-0720 is classified as a critical vulnerability that can lead to serious security issues if not addressed.
How do I fix CVE-2011-0720?
To address CVE-2011-0720, update your Plone installation to version 4.0.4 or later, or apply the specific patches provided by your vendor.
Which versions of Plone are affected by CVE-2011-0720?
CVE-2011-0720 affects multiple versions of Plone from 2.5 to 4.0, including several intermediate versions.
What are some common impacts of CVE-2011-0720?
The impacts of CVE-2011-0720 may include unauthorized access to sensitive data and compromise of web applications.
Is there a workaround for CVE-2011-0720?
While updating is the recommended solution for CVE-2011-0720, you may also consider restricting access to vulnerable components as a temporary workaround.