HIGH 8.8 PyPI

Plone SQL Injection Vulnerability

GHSA-hhmf-7rgg-gcw5 · CVE-2020-7939 · PYSEC-2020-88

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)

Ready to move

Start Securing

Free, no credit card | First findings in minutes