plone: unauthorized remote administrative access
Published Feb 3, 2011
9.3
CRITICALCVSS 4.0
EPSS 3.20%
Description
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
Affected products
No data.
- 2.5
- 2.5.1
- 2.5.2
- 2.5.3
- 2.5.4
- 2.5.5
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.1
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5.1
- 3.1.6
- 3.1.7
- 3.2
- 3.2.1
- 3.2.2
- 3.2.3
- 3.3
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 4.0
No data.
CLuster Suite for RHEL 4
conga-0:0.11.2-4.el4.2
Fixed · RHSA-2011:0393
Red Hat Enterprise Linux 5
conga-0:0.12.2-24.el5_6.1
Fixed · RHSA-2011:0394
Red Hat Enterprise Linux 5
conga
Affected
Red Hat Enterprise Linux 6
luci
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CLuster Suite for RHEL 4 | conga-0:0.11.2-4.el4.2 | Fixed | RHSA-2011:0393 |
| Red Hat Enterprise Linux 5 | conga-0:0.12.2-24.el5_6.1 | Fixed | RHSA-2011:0394 |
| Red Hat Enterprise Linux 5 | conga | Affected | n/a |
| Red Hat Enterprise Linux 6 | luci | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.20% (0.03198) | 87.68th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.11% (0.03111) | 86.05th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.41% (0.01407) | 78.71th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.44% (0.02442) | 75.25th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.41% (0.01407) | 79.16th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.90% (0.01902) | 89.02th | v3 (v2023.03.01) |
| Jul 10, 2024 | 1.90% (0.01902) | 88.67th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.90% (0.01902) | 86.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.17% (0.02172) | 80.77th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.17% (0.02172) | 78.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.17% (0.02172) | 57.73th | v2 (v2022.01.01) |
References (21)
- http://osvdb.org/70753 vdb-entryx_refsource_OSVDB
- http://plone.org/products/plone/security/advisories/cve-2011-0720 x_refsource_CONFIRMVendor Advisory
- http://secunia.com/advisories/43146 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/43914 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0393.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2011-0394.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/46102 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1025258 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2011/0796 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2011-0720 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=676961 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65099 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-3v28-9jjp-4g5w Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-13.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2011-0720
- https://plone.org/products/plone-hotfix/releases/CVE-2011-0720/logchecker.py
- https://seclists.org/fulldisclosure/2011/Apr/293
- https://web.archive.org/web/20110505051314/http://secunia.com/advisories/43914
- https://web.archive.org/web/20110826134658/http://secunia.com/advisories/43146
- https://web.archive.org/web/20200229153953/http://www.securityfocus.com/bid/46102
- https://www.cve.org/CVERecord?id=CVE-2011-0720
Change history (0)
No recorded changes yet.