---
id: CVE-2000-0062
aliases:
  - GHSA-wcwp-r3fj-mm3p
  - PYSEC-2026-762
title: Zope DTML implementation Improper Authentication
summary: Zope DTML implementation Improper Authentication
severity: high
vendor: zope
product: zope
ecosystem: pip
affected:
  - 'zope >= 2.2.0, <= 2.2.4'
published: '2022-04-30'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-wcwp-r3fj-mm3p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2000-0062'
  - url: >-
      https://web.archive.org/web/20010218085743/http://www.securityfocus.com/bid/922
tags:
  - osv
  - pip
epss: 0.02236
epssPercentile: 0.8185
ingestedAt: '2026-07-08T18:25:53.610Z'
---

## Overview

The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.

## Affected packages

- `zope >= 2.2.0, <= 2.2.4`

## Remediation

Refer to the advisory for the patched release.
