CVE-2020-7939: SQL Injection
Published Jan 23, 2020
·Updated
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
Affected Software
2 affected components
pip/Plone>=4.0<=5.2.1
Plone plone>=4.0.0<=5.2.1
Event History
Jan 23, 2020
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
05:07 PM
Frequently Asked Questions
1
What is CVE-2020-7939?
CVE-2020-7939 is a vulnerability that allows users to perform unwanted SQL queries through SQL Injection in DTML or connection objects in Plone 4.0 through 5.2.1.
2
How severe is CVE-2020-7939?
CVE-2020-7939 is a high severity vulnerability with a CVSS score of 8.8.
3
Which software versions are affected by CVE-2020-7939?
Plone versions 4.0 through 5.2.1 are affected by CVE-2020-7939.
4
How can users exploit CVE-2020-7939?
Users can exploit CVE-2020-7939 by performing SQL Injection attacks in DTML or connection objects in Plone.
5
Is there a fix for CVE-2020-7939?
Yes, there is a hotfix available for CVE-2020-7939. Users can refer to the Plone security advisory for instructions on applying the fix.