{"id":"CVE-2011-1948","aliases":["GHSA-p7h9-vf92-5fj5","PYSEC-2011-14","PYSEC-2026-2965","PYSEC-2026-2966"],"title":"Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool","summary":"Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","vendor":"products-passwordresettool","product":"products-passwordresettool","ecosystem":"pip","affected":["products-passwordresettool < 2.0.6","products-cmfplone < 4.0.7","products-cmfplone >= 4.1a1, < 4.1rc3","plone < 4.1.1"],"patched":["products-passwordresettool 2.0.6","products-cmfplone 4.0.7","products-cmfplone 4.1rc3","plone 4.1.1"],"published":"2018-07-23","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-p7h9-vf92-5fj5","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1948"},{"url":"https://access.redhat.com/errata/RHSA-2012:0151"},{"url":"https://access.redhat.com/security/cve/CVE-2011-1948"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=711494"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/67693"},{"url":"https://github.com/advisories/GHSA-p7h9-vf92-5fj5"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-14.yaml"},{"url":"http://plone.org/products/plone/security/advisories/CVE-2011-1948"}],"tags":["osv","pip"],"epss":0.02389,"epssPercentile":0.83067,"ingestedAt":"2026-07-13T18:58:01.280Z","slug":"CVE-2011-1948","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.\n\n## Affected packages\n\n- `products-passwordresettool < 2.0.6`\n- `products-cmfplone < 4.0.7`\n- `products-cmfplone >= 4.1a1, < 4.1rc3`\n- `plone < 4.1.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `products-passwordresettool 2.0.6`\n- `products-cmfplone 4.0.7`\n- `products-cmfplone 4.1rc3`\n- `plone 4.1.1`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}