{"id":"CVE-2011-4030","aliases":[],"url":"https://o3.security/vulnerability/CVE-2011-4030","summary":"The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers…","details":"The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.","published":"2011-10-10T10:55:06.957","modified":"2026-06-16T23:34:18.957","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"FIX","url":"http://plone.org/products/plone-hotfix/releases/20110928"},{"type":"FIX","url":"http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip"},{"type":"FIX","url":"http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"},{"type":"WEB","url":"http://secunia.com/advisories/46323"},{"type":"WEB","url":"http://www.securityfocus.com/bid/50287"},{"type":"FIX","url":"http://plone.org/products/plone-hotfix/releases/20110928"},{"type":"FIX","url":"http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip"},{"type":"FIX","url":"http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0"},{"type":"WEB","url":"http://secunia.com/advisories/46323"},{"type":"WEB","url":"http://www.securityfocus.com/bid/50287"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:34:18.957"}}