Description

Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.

Description source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 5.2.3 · Fixed in 5.2.3affected
GitHub AdvisoryBefore 2.6.8 · Fixed in 2.6.8affected
GitHub AdvisoryBefore 3.2.10 · Fixed in 3.2.10affected
GitHub AdvisoryBefore 4.1.6 · Fixed in 4.1.6affected
GitHub AdvisoryBefore 1.6.3 · Fixed in 1.6.3affected

References

6