Medium severity6.1NVD Advisory· Published Nov 25, 2019· Updated Jun 16, 2026
CVE-2011-4924
CVE-2011-4924
Description
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
zopePyPI | >= 3.1.1, < 3.7.3 | 3.7.3 |
zope2PyPI | < 2.12.22 | 2.12.22 |
zope2PyPI | >= 2.13.0a1, < 2.13.12 | 2.13.12 |
Affected products
4- ghsa-coords2 versions
>= 3.1.1, < 3.7.3+ 1 more
- (no CPE)range: >= 3.1.1, < 3.7.3
- (no CPE)range: < 2.12.22
- zope/zope2, zope3v5Range: 2.8.x before 2.8.12
Patches
Vulnerability mechanics
References
11- www.openwall.com/lists/oss-security/2012/01/19/16nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2012/01/19/17nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2012/01/19/18nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2012/01/19/19nvdMailing ListThird Party AdvisoryWEB
- access.redhat.com/security/cve/cve-2011-4924nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-vh6g-786f-hxxpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-4924ghsaADVISORY
- security-tracker.debian.org/tracker/CVE-2011-4924nvdThird Party AdvisoryWEB
- github.com/zopefoundation/Zope/commit/37e4ea774acc668f6b430a45a6ab1e359710f590ghsaWEB
- github.com/zopefoundation/Zope/commit/a0655194cb39ad88ce3323a3e489927c5f979c44ghsaWEB
News mentions
0No linked articles in our index yet.