—
PYSEC-2020-88
Quick fix
PYSEC-2020-88 — plone: upgrade to the fixed version with the command below.
pip install --upgrade 'plone>=5.2.2'Details
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://plone.org/security/hotfix/20200121[WEB]
- https://plone.org/security/hotfix/20200121/sql-injection-in-dtml-or-in-connection-objects[WEB]
- https://www.openwall.com/lists/oss-security/2020/01/22/1[WEB]
- http://www.openwall.com/lists/oss-security/2020/01/24/1[WEB]
- https://github.com/advisories/GHSA-hhmf-7rgg-gcw5[ADVISORY]