CVE-2020-7936: Medium severity Plone plone vulnerability
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 5.2.2 - Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 5.1.7 - Upgrade
Upgrade
pip/Ploneto a version that resolves this vulnerability.Fixed in 4.3.20
Event History
Frequently Asked Questions
What is CVE-2020-7936?
CVE-2020-7936 is a vulnerability in Plone 4.0 through 5.2.1 that allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
How severe is the CVE-2020-7936 vulnerability?
The severity of CVE-2020-7936 is medium with a CVSS score of 6.1.
Which versions of Plone are affected by CVE-2020-7936?
Plone 4.0 through 5.2.1 are affected by CVE-2020-7936.
How can I fix the CVE-2020-7936 vulnerability?
To fix the CVE-2020-7936 vulnerability, upgrade Plone to version 5.2.2, 5.1.7, or 4.3.20 depending on the affected version.
Where can I find more information about CVE-2020-7936?
You can find more information about CVE-2020-7936 on the National Vulnerability Database (NVD) and the Plone website.