First published: Thu Jan 23 2020(Updated: )
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Plone | >=4.0<=5.2.1 | |
Plone Plone | >=4.0.0<=5.2.1 | |
>=4.0.0<=5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7939 is a vulnerability that allows users to perform unwanted SQL queries through SQL Injection in DTML or connection objects in Plone 4.0 through 5.2.1.
CVE-2020-7939 is a high severity vulnerability with a CVSS score of 8.8.
Plone versions 4.0 through 5.2.1 are affected by CVE-2020-7939.
Users can exploit CVE-2020-7939 by performing SQL Injection attacks in DTML or connection objects in Plone.
Yes, there is a hotfix available for CVE-2020-7939. Users can refer to the Plone security advisory for instructions on applying the fix.