CVE-2020-28734: XEE
Published Dec 30, 2020
·Updated
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
Affected Software
6 affected componentsFixes available
pip/plone.supermodel<1.6.3
1.6.3
pip/plone.app.dexterity<2.6.8
2.6.8
pip/plone.app.theming<4.1.6
4.1.6
pip/plone.app.event<3.2.10
3.2.10
pip/Plone<5.2.3
5.2.3
Plone plone<5.2.3
Remediation
Patch Available
Event History
Dec 30, 2020
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
Description
Apr 7, 2021
Advisory Published
09:13 PM
Frequently Asked Questions
1
What is CVE-2020-28734?
CVE-2020-28734 is a vulnerability in Plone before version 5.2.3 which allows XXE attacks via a feature that is explicitly only available to the Manager role.
2
How severe is CVE-2020-28734?
CVE-2020-28734 has a severity score of 8.8 (high).
3
Which software versions are affected by CVE-2020-28734?
Plone versions before 5.2.3 are affected by CVE-2020-28734.
4
What is the remedy for CVE-2020-28734?
To fix CVE-2020-28734, update the affected software versions to Plone 5.2.3 or later.
5
Where can I find more information about CVE-2020-28734?
More information about CVE-2020-28734 can be found at the following references: [Link 1](https://nvd.nist.gov/vuln/detail/CVE-2020-28734), [Link 2](https://github.com/plone/Products.CMFPlone/issues/3209), [Link 3](https://dist.plone.org/release/5.2.3/RELEASE-NOTES.txt).