CVE-2011-1950Medium· 6.5▾ Twilight⚠ Exploited in the wildPlone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0.5 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.6%
1.6% → 2.3%
plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exploited in the wild in June 2011.
plone-app-users >= 1.0a1, < 1.0.5plone-app-users >= 1.1b1, < 1.1.1plone >= 4.0.1, < 4.0.6plone >= 4.1.0, < 4.1.1Upgrade to a patched release:
plone-app-users 1.0.5plone-app-users 1.1.1plone 4.0.6plone 4.1.1