Back

HIGH

plone: Privilege escalation via plone.app.users (Plone v4.0 and v4.1 specific)

Published Jun 6, 2011

Description

plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exploited in the wild in June 2011.

Affected products

Remediation

Red Hat statement

Not Vulnerable. This issue does not affect the version of conga as shipped with Red Hat Enterprise Linux 5 and Red Hat Cluster Suite EL4

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 6, 2011
Updated Aug 6, 2024
Reserved May 9, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 31, 2011
GHSA-2QX8-589J-GCPX