CVE-2020-7940

Description

Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.34

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-7936,CVE-2020-7940 are fixed in Python-plone 4.3.20Windows
Vulnerabilities CVE-2020-7936,CVE-2020-7940 are fixed in Python-plone 5.1.7Windows
Vulnerabilities CVE-2020-7936,CVE-2020-7938,CVE-2020-7940 are fixed in Python-plone 5.2.2Windows
Vulnerabilities CVE-2020-7936,CVE-2020-7940 are fixed in Python-plone for linux 4.3.20Linux
Vulnerabilities CVE-2020-7936,CVE-2020-7940 are fixed in Python-plone for linux 5.1.7Linux
Vulnerabilities CVE-2020-7936,CVE-2020-7938,CVE-2020-7940 are fixed in Python-plone for linux 5.2.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234