First published: Wed Dec 30 2020(Updated: )
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/plone.supermodel | <1.6.3 | 1.6.3 |
pip/plone.app.dexterity | <2.6.8 | 2.6.8 |
pip/plone.app.theming | <4.1.6 | 4.1.6 |
pip/plone.app.event | <3.2.10 | 3.2.10 |
pip/Plone | <5.2.3 | 5.2.3 |
Plone Plone | <5.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28734 is a vulnerability in Plone before version 5.2.3 which allows XXE attacks via a feature that is explicitly only available to the Manager role.
CVE-2020-28734 has a severity score of 8.8 (high).
Plone versions before 5.2.3 are affected by CVE-2020-28734.
To fix CVE-2020-28734, update the affected software versions to Plone 5.2.3 or later.
More information about CVE-2020-28734 can be found at the following references: [Link 1](https://nvd.nist.gov/vuln/detail/CVE-2020-28734), [Link 2](https://github.com/plone/Products.CMFPlone/issues/3209), [Link 3](https://dist.plone.org/release/5.2.3/RELEASE-NOTES.txt).