CVE-2020-7939

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
23/01/2020
Last modified:
24/01/2020

Description

SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:* 4.0.0 (including) 5.2.1 (including)