{"api_version":"1","generated_at":"2026-07-23T19:43:51+00:00","cve":"CVE-2011-4924","urls":{"html":"https://cve.report/CVE-2011-4924","api":"https://cve.report/api/cve/CVE-2011-4924.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-4924","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-4924"},"summary":{"title":"CVE-2011-4924","description":"Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-11-25 18:15:00","updated_at":"2019-12-05 16:01:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2012/01/19/16","name":"http://www.openwall.com/lists/oss-security/2012/01/19/16","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE-2011-4924 assignment notification -- Zope2, Zope3: Incomplete\n upstream fix for CVE-2010-1104 issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security-tracker.debian.org/tracker/CVE-2011-4924","name":"https://security-tracker.debian.org/tracker/CVE-2011-4924","refsource":"MISC","tags":["Third Party Advisory"],"title":"CVE-2011-4924","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/cve-2011-4924","name":"https://access.redhat.com/security/cve/cve-2011-4924","refsource":"MISC","tags":["Third Party Advisory"],"title":"CVE-2011-4924 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/01/19/17","name":"http://www.openwall.com/lists/oss-security/2012/01/19/17","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE-2011-4924 assignment notification -- Zope2,\n Zope3: Incomplete upstream fix for CVE-2010-1104 issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"771920 – (CVE-2011-4924) CVE-2011-4924 Zope: Incomplete upstream patch for CVE-2010-1104 issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/01/19/18","name":"http://www.openwall.com/lists/oss-security/2012/01/19/18","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE-2011-4924 assignment notification -- Zope2,\n Zope3: Incomplete upstream fix for CVE-2010-1104 issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/01/19/19","name":"http://www.openwall.com/lists/oss-security/2012/01/19/19","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE-2011-4924 assignment notification -- Zope2,\n Zope3: Incomplete upstream fix for CVE-2010-1104 issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-4924","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4924","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"4924","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zope","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4924","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zope","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4924","vulnerable":"1","versionEndIncluding":"3.4.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zope","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2011-4924","qid":"996739","title":"Python (Pip) Security Update for zope (GHSA-vh6g-786f-hxxp)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2011-4924","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Incomplete upstream patch for CVE-2010-1104 issue"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"zope","product":{"product_data":[{"product_name":"zope2, zope3","version":{"version_data":[{"version_affected":"=","version_value":"2.8.x before 2.8.12"},{"version_affected":"=","version_value":"2.9.x before 2.9.12"},{"version_affected":"=","version_value":"2.10.x before 2.10.11"},{"version_affected":"=","version_value":"2.11.x before 2.11.6"},{"version_affected":"=","version_value":"and 2.12.x before 2.12.3"},{"version_affected":"=","version_value":"3.1.1through 3.4.1"}]}}]}}]}},"references":{"reference_data":[{"url":"http://www.openwall.com/lists/oss-security/2012/01/19/16","refsource":"MISC","name":"http://www.openwall.com/lists/oss-security/2012/01/19/16"},{"url":"http://www.openwall.com/lists/oss-security/2012/01/19/17","refsource":"MISC","name":"http://www.openwall.com/lists/oss-security/2012/01/19/17"},{"url":"http://www.openwall.com/lists/oss-security/2012/01/19/18","refsource":"MISC","name":"http://www.openwall.com/lists/oss-security/2012/01/19/18"},{"url":"http://www.openwall.com/lists/oss-security/2012/01/19/19","refsource":"MISC","name":"http://www.openwall.com/lists/oss-security/2012/01/19/19"},{"url":"https://access.redhat.com/security/cve/cve-2011-4924","refsource":"MISC","name":"https://access.redhat.com/security/cve/cve-2011-4924"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924"},{"url":"https://security-tracker.debian.org/tracker/CVE-2011-4924","refsource":"MISC","name":"https://security-tracker.debian.org/tracker/CVE-2011-4924"}]}},"nvd":{"publishedDate":"2019-11-25 18:15:00","lastModifiedDate":"2019-12-05 16:01:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1.1","versionEndIncluding":"3.4.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:*","versionStartIncluding":"2.12.0","versionEndExcluding":"2.12.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:*","versionStartIncluding":"2.11.0","versionEndExcluding":"2.11.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:*","versionStartIncluding":"2.10.0","versionEndExcluding":"2.10.11","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:*","versionStartIncluding":"2.9.0","versionEndExcluding":"2.9.12","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zope:zope:*:*:*:*:*:*:*:*","versionStartIncluding":"2.8.0","versionEndExcluding":"2.8.12","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"4924","Ordinal":"52738","Title":"CVE-2011-4924","CVE":"CVE-2011-4924","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"4924","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104","Type":"Description","Title":null},{"CveYear":"2011","CveId":"4924","Ordinal":"2","NoteData":"2019-11-25","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"4924","Ordinal":"3","NoteData":"2019-11-25","Type":"Other","Title":"Modified"}]}}}