CVE-2011-1948: XSS
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1948 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1948 [2] http://www.securityfocus.com/archive/1/archive/1/518155/100/0/threaded [3] http://plone.org/products/plone/security/advisories/CVE-2011-1948 [4] http://www.securityfocus.com/bid/48005 [5] http://secunia.com/advisories/44775 [6] http://secunia.com/advisories/44776 [7] http://xforce.iss.net/xforce/xfdb/67693
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1948?
CVE-2011-1948 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2011-1948?
To fix CVE-2011-1948, upgrade to Plone version 4.1.1 or later.
Which versions of Plone are affected by CVE-2011-1948?
CVE-2011-1948 affects Plone versions from 1.0 up to 4.1 inclusive.
What types of attacks can exploit CVE-2011-1948?
CVE-2011-1948 can allow remote attackers to inject arbitrary web scripts into affected Plone applications.
Is there a workaround for CVE-2011-1948 if I cannot apply the update?
There is no recommended workaround for CVE-2011-1948, and updating to a secure version is strongly advised.