Description
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
Remediation
References
Related Vulnerabilities
Roundcube Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-4076)
WordPress Plugin Portfolio Gallery-Photo Gallery Unspecified Vulnerability (2.3.0)
WordPress Plugin WP-DBManager Arbitrary File Deletion (2.79.1)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31546)