CVE-2020-7937: XSS
Published Jan 23, 2020
·Updated
An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.
Affected Software
2 affected components
pip/Plone>=5.0<=5.2.1
Plone plone>=5.0<=5.2.1
Event History
Jan 23, 2020
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
via GitHub·05:07 PM
Frequently Asked Questions
1
What is CVE-2020-7937?
CVE-2020-7937 is an XSS vulnerability in the title field in Plone 5.0 through 5.2.1.
2
Who is affected by CVE-2020-7937?
Users of Plone versions 5.0 through 5.2.1 are affected by CVE-2020-7937.
3
What is the severity of CVE-2020-7937?
The severity of CVE-2020-7937 is medium with a CVSS score of 5.4.
4
How does CVE-2020-7937 work?
CVE-2020-7937 allows users with a certain privilege level to insert JavaScript into the title field, which will be executed when other users access the site.
5
How can I mitigate CVE-2020-7937?
To mitigate CVE-2020-7937, apply the hotfix provided by Plone and upgrade to version 5.2.2 or higher.