First published: Thu Jan 23 2020(Updated: )
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/plone.app.contenttypes | <2.1.6 | |
pip/Plone | >=4.3<=5.2.1 | |
Plone Plone | >=4.3.0<=5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-7941 is critical with a CVSS score of 9.8.
CVE-2020-7941 allows users to overwrite content without needing write permission, which can lead to privilege escalation.
Plone versions 4.3 through 5.2.1 are affected by CVE-2020-7941.
To fix CVE-2020-7941, it is recommended to apply the hotfix provided by Plone.
More information about CVE-2020-7941 can be found on the NIST National Vulnerability Database (NVD) and the Plone security advisory pages.