First published: Thu Jan 23 2020(Updated: )
An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plone Plone | >=5.0<=5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7937 is an XSS vulnerability in the title field in Plone 5.0 through 5.2.1.
Users of Plone versions 5.0 through 5.2.1 are affected by CVE-2020-7937.
The severity of CVE-2020-7937 is medium with a CVSS score of 5.4.
CVE-2020-7937 allows users with a certain privilege level to insert JavaScript into the title field, which will be executed when other users access the site.
To mitigate CVE-2020-7937, apply the hotfix provided by Plone and upgrade to version 5.2.2 or higher.