SQL Injection Vulnerability in Plone by Zope
CVE-2020-7939
8.8HIGH
What is CVE-2020-7939?
A SQL Injection vulnerability exists in Plone versions 4.0 through 5.2.1 due to improper handling of user input in DTML or within connection objects. This flaw enables a malicious user to execute arbitrary SQL queries, potentially compromising the integrity and confidentiality of the database. It is crucial for users of affected versions to apply the latest security hotfix to mitigate this risk.
