Fedora Account System
Red Hat Associate
Red Hat Customer
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.) References: https://plone.org/security/hotfix/20200121/sql-injection-in-dtml-or-in-connection-objects https://plone.org/security/hotfix/20200121
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-7939