Safety vulnerability ID: 37787
The information on this page was manually curated by our Cybersecurity Intelligence Team.
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.) See: CVE-2020-7939.
Latest version: 6.1.1
The Plone Content Management System
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
MISC:https://plone.org/security/hotfix/20200121: https://plone.org/security/hotfix/20200121
MISC:https://plone.org/security/hotfix/20200121/sql-injection-in-dtml-or-in-connection-objects: https://plone.org/security/hotfix/20200121/sql-injection-in-dtml-or-in-connection-objects
MISC:https://www.openwall.com/lists/oss-security/2020/01/22/1: https://www.openwall.com/lists/oss-security/2020/01/22/1
MLIST:[oss-security] 20200124 Re: Plone security hotfix 20200121: http://www.openwall.com/lists/oss-security/2020/01/24/1
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application