Vulnerability Details CVE-2020-7941
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-7941
-
cpe:2.3:a:plone:plone:4.3.0
-
cpe:2.3:a:plone:plone:4.3.1
-
cpe:2.3:a:plone:plone:4.3.10
-
cpe:2.3:a:plone:plone:4.3.11
-
cpe:2.3:a:plone:plone:4.3.12
-
cpe:2.3:a:plone:plone:4.3.13
-
cpe:2.3:a:plone:plone:4.3.14
-
cpe:2.3:a:plone:plone:4.3.15
-
cpe:2.3:a:plone:plone:4.3.16
-
cpe:2.3:a:plone:plone:4.3.17
-
cpe:2.3:a:plone:plone:4.3.18
-
cpe:2.3:a:plone:plone:4.3.19
-
cpe:2.3:a:plone:plone:4.3.2
-
cpe:2.3:a:plone:plone:4.3.20
-
cpe:2.3:a:plone:plone:4.3.3
-
cpe:2.3:a:plone:plone:4.3.4
-
cpe:2.3:a:plone:plone:4.3.5
-
cpe:2.3:a:plone:plone:4.3.6
-
cpe:2.3:a:plone:plone:4.3.7
-
cpe:2.3:a:plone:plone:4.3.8
-
cpe:2.3:a:plone:plone:4.3.9
-
cpe:2.3:a:plone:plone:5.0
-
cpe:2.3:a:plone:plone:5.0.1
-
cpe:2.3:a:plone:plone:5.0.10
-
cpe:2.3:a:plone:plone:5.0.2
-
cpe:2.3:a:plone:plone:5.0.3
-
cpe:2.3:a:plone:plone:5.0.4
-
cpe:2.3:a:plone:plone:5.0.5
-
cpe:2.3:a:plone:plone:5.0.6
-
cpe:2.3:a:plone:plone:5.0.7
-
cpe:2.3:a:plone:plone:5.0.8
-
cpe:2.3:a:plone:plone:5.0.9
-
cpe:2.3:a:plone:plone:5.1
-
cpe:2.3:a:plone:plone:5.1.1
-
cpe:2.3:a:plone:plone:5.1.2
-
cpe:2.3:a:plone:plone:5.1.3
-
cpe:2.3:a:plone:plone:5.1.4
-
cpe:2.3:a:plone:plone:5.1.5
-
cpe:2.3:a:plone:plone:5.1.6
-
cpe:2.3:a:plone:plone:5.1.7
-
cpe:2.3:a:plone:plone:5.1a1
-
cpe:2.3:a:plone:plone:5.1a2
-
cpe:2.3:a:plone:plone:5.1b2
-
cpe:2.3:a:plone:plone:5.1b3
-
cpe:2.3:a:plone:plone:5.1b4
-
cpe:2.3:a:plone:plone:5.1rc1
-
cpe:2.3:a:plone:plone:5.1rc2
-
cpe:2.3:a:plone:plone:5.2
-
cpe:2.3:a:plone:plone:5.2.0
-
cpe:2.3:a:plone:plone:5.2.1