CVE-2011-3587 is an unspecified remote code execution vulnerability affecting Zope 2.12.x and 2.13.x, and Plone versions 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, stemming from issues with the p_ class in OFS/misc_.py and Python module usage. This critical vulnerability has a CVSS score of 9.3, indicating a network-based attack with medium complexity, allowing for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, public exploit modules exist for Metasploit and ExploitDB, suggesting a high potential for exploitation, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:plone:plone:4.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:a:plone:plone:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:a:plone:plone:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:a:plone:plone:4.0.3:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:a:plone:plone:4.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.