5.4
CVSSv3

CVE-2020-7937

Published: 23/01/2020 Updated: 24/01/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An XSS issue in the title field in Plone 5.0 up to and including 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone

Mailing Lists

We have received CVE numbers from mitreorg Thanks See inline below On 21/01/2020 23:49, Maurits van Rees wrote: CVE-2020-7938 CVE-2020-7936 CVE-2020-7940 CVE-2020-7941 CVE-2020-7939 CVE-2020-7937 -- Maurits van Rees mauritsvanreesorg/ ...