{"id":"GHSA-vh6g-786f-hxxp","summary":"Zope XSS Vulnerability","details":"Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104","aliases":["CVE-2011-4924","PYSEC-2026-3440","PYSEC-2026-766"],"modified":"2026-07-13T16:43:17.362847440Z","published":"2022-04-22T00:24:16Z","database_specific":{"github_reviewed_at":"2024-01-15T17:29:15Z","nvd_published_at":"2019-11-25T18:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4924"},{"type":"WEB","url":"https://github.com/zopefoundation/Zope/commit/37e4ea774acc668f6b430a45a6ab1e359710f590"},{"type":"WEB","url":"https://github.com/zopefoundation/Zope/commit/a0655194cb39ad88ce3323a3e489927c5f979c44"},{"type":"WEB","url":"https://access.redhat.com/security/cve/cve-2011-4924"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924"},{"type":"PACKAGE","url":"https://github.com/zopefoundation/Zope"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2011-4924"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/01/19/16"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/01/19/17"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/01/19/18"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/01/19/19"}],"affected":[{"package":{"name":"zope","ecosystem":"PyPI","purl":"pkg:pypi/zope"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.1"},{"fixed":"3.7.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-vh6g-786f-hxxp/GHSA-vh6g-786f-hxxp.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12.22"}]}],"versions":["2.12.0","2.12.0.a1","2.12.0a2","2.12.0a3","2.12.0a4","2.12.0b1","2.12.0b2","2.12.0b3","2.12.0b4","2.12.0c1","2.12.1","2.12.10","2.12.11","2.12.12","2.12.13","2.12.14","2.12.15","2.12.16","2.12.17","2.12.18","2.12.19","2.12.2","2.12.20","2.12.21","2.12.3","2.12.4","2.12.5","2.12.6","2.12.7","2.12.8","2.12.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-vh6g-786f-hxxp/GHSA-vh6g-786f-hxxp.json"}},{"package":{"name":"zope2","ecosystem":"PyPI","purl":"pkg:pypi/zope2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.13.0a1"},{"fixed":"2.13.12"}]}],"versions":["2.13.0","2.13.0a1","2.13.0a2","2.13.0a3","2.13.0a4","2.13.0b1","2.13.0c1","2.13.1","2.13.10","2.13.11","2.13.2","2.13.3","2.13.4","2.13.5","2.13.6","2.13.7","2.13.8","2.13.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-vh6g-786f-hxxp/GHSA-vh6g-786f-hxxp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}