CVE-2012-5491
Summary
| CVE | CVE-2012-5491 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-09-30 14:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Plone | Plone | 1.0 | All | All | All |
| Application | Plone | Plone | 1.0.1 | All | All | All |
| Application | Plone | Plone | 1.0.2 | All | All | All |
| Application | Plone | Plone | 1.0.3 | All | All | All |
| Application | Plone | Plone | 1.0.4 | All | All | All |
| Application | Plone | Plone | 1.0.5 | All | All | All |
| Application | Plone | Plone | 1.0.6 | All | All | All |
| Application | Plone | Plone | 2.0 | All | All | All |
| Application | Plone | Plone | 2.0.1 | All | All | All |
| Application | Plone | Plone | 2.0.2 | All | All | All |
| Application | Plone | Plone | 2.0.3 | All | All | All |
| Application | Plone | Plone | 2.0.4 | All | All | All |
| Application | Plone | Plone | 2.0.5 | All | All | All |
| Application | Plone | Plone | 2.1 | All | All | All |
| Application | Plone | Plone | 2.1.1 | All | All | All |
| Application | Plone | Plone | 2.1.2 | All | All | All |
| Application | Plone | Plone | 2.1.3 | All | All | All |
| Application | Plone | Plone | 2.1.4 | All | All | All |
| Application | Plone | Plone | 2.5 | All | All | All |
| Application | Plone | Plone | 2.5.1 | All | All | All |
| Application | Plone | Plone | 2.5.2 | All | All | All |
| Application | Plone | Plone | 2.5.3 | All | All | All |
| Application | Plone | Plone | 2.5.4 | All | All | All |
| Application | Plone | Plone | 2.5.5 | All | All | All |
| Application | Plone | Plone | 3.0 | All | All | All |
| Application | Plone | Plone | 3.0.1 | All | All | All |
| Application | Plone | Plone | 3.0.2 | All | All | All |
| Application | Plone | Plone | 3.0.3 | All | All | All |
| Application | Plone | Plone | 3.0.4 | All | All | All |
| Application | Plone | Plone | 3.0.5 | All | All | All |
| Application | Plone | Plone | 3.0.6 | All | All | All |
| Application | Plone | Plone | 3.1 | All | All | All |
| Application | Plone | Plone | 3.1.1 | All | All | All |
| Application | Plone | Plone | 3.1.2 | All | All | All |
| Application | Plone | Plone | 3.1.3 | All | All | All |
| Application | Plone | Plone | 3.1.4 | All | All | All |
| Application | Plone | Plone | 3.1.5.1 | All | All | All |
| Application | Plone | Plone | 3.1.6 | All | All | All |
| Application | Plone | Plone | 3.1.7 | All | All | All |
| Application | Plone | Plone | 3.2 | All | All | All |
| Application | Plone | Plone | 3.2.1 | All | All | All |
| Application | Plone | Plone | 3.2.2 | All | All | All |
| Application | Plone | Plone | 3.2.3 | All | All | All |
| Application | Plone | Plone | 3.3 | All | All | All |
| Application | Plone | Plone | 3.3.1 | All | All | All |
| Application | Plone | Plone | 3.3.2 | All | All | All |
| Application | Plone | Plone | 3.3.3 | All | All | All |
| Application | Plone | Plone | 3.3.4 | All | All | All |
| Application | Plone | Plone | 3.3.5 | All | All | All |
| Application | Plone | Plone | 4.0 | All | All | All |
| Application | Plone | Plone | 4.0.1 | All | All | All |
| Application | Plone | Plone | 4.0.2 | All | All | All |
| Application | Plone | Plone | 4.0.3 | All | All | All |
| Application | Plone | Plone | 4.0.4 | All | All | All |
| Application | Plone | Plone | 4.0.5 | All | All | All |
| Application | Plone | Plone | 4.0.6.1 | All | All | All |
| Application | Plone | Plone | 4.1 | All | All | All |
| Application | Plone | Plone | 4.1.4 | All | All | All |
| Application | Plone | Plone | 4.1.5 | All | All | All |
| Application | Plone | Plone | 4.1.6 | All | All | All |
| Application | Plone | Plone | 4.2 | All | All | All |
| Application | Plone | Plone | 4.2 | a1 | All | All |
| Application | Plone | Plone | 4.2 | a2 | All | All |
| Application | Plone | Plone | 4.2 | b1 | All | All |
| Application | Plone | Plone | 4.2 | b2 | All | All |
| Application | Plone | Plone | 4.2 | rc1 | All | All |
| Application | Plone | Plone | 4.2 | rc2 | All | All |
| Application | Plone | Plone | 4.2.0.1 | All | All | All |
| Application | Plone | Plone | 4.2.1 | All | All | All |
| Application | Plone | Plone | 4.2.1.1 | All | All | All |
| Application | Plone | Plone | 4.3 | All | All | All |
| Application | Plone | Plone | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Plone Hotfix 20121106 — Plone CMS: Open Source Content Management | af854a3a-2127-422b-91ae-364da2661108 | plone.org | Patch |
| oss-security - Re: Re: CVE Request - Zope / Plone: Multiple vectors corrected within 20121106 fix | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Form detail exposure — Plone CMS: Open Source Content Management | af854a3a-2127-422b-91ae-364da2661108 | plone.org | Vendor Advisory |
| Products.CMFPlone/CHANGES.txt at 4.2.3 · plone/Products.CMFPlone · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.