Plone CMS Improper Restriction of XML External Entity Reference Vulnerability - CVE-2020-28736 - Vulnerability Database

Plone CMS Improper Restriction of XML External Entity Reference Vulnerability - CVE-2020-28736

High
Reference: CVE-2020-28736
Title: Plone CMS Improper Restriction of XML External Entity Reference Vulnerability
Overview:

Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore only available to the Manager role).