First published: Mon Jun 06 2011(Updated: )
plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exploited in the wild in June 2011.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Plone Plone | =4.1 | |
Plone Plone | =4.0 | |
pip/Plone | >=4.1.0<4.1.1 | 4.1.1 |
pip/Plone | >=4.0.1<4.0.6 | 4.0.6 |
pip/plone.app.users | >=1.1b1<1.1.1 | 1.1.1 |
pip/plone.app.users | >=1.0a1<1.0.5 | 1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1950 is considered to have a medium severity due to the potential for unauthorized account modification.
To fix CVE-2011-1950, upgrade to Plone version 4.1.1 or 4.0.6 or update plone.app.users to version 1.1.1 or 1.0.5.
CVE-2011-1950 affects Plone versions 4.0 and 4.1.
Yes, remote authenticated users can exploit CVE-2011-1950 to modify properties of arbitrary accounts.
CVE-2011-1950 was exploited in the wild in June 2011.