Plone CMS Improper Restriction of XML External Entity Reference Vulnerability - CVE-2020-28734 - Vulnerability Database

Plone CMS Improper Restriction of XML External Entity Reference Vulnerability - CVE-2020-28734

High
Reference: CVE-2020-28734
Title: Plone CMS Improper Restriction of XML External Entity Reference Vulnerability
Overview:

Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.