First published: Wed Dec 30 2020(Updated: )
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/plone.supermodel | <1.6.3 | 1.6.3 |
pip/plone.app.dexterity | <2.6.8 | 2.6.8 |
pip/plone.app.theming | <4.1.6 | 4.1.6 |
pip/plone.app.event | <3.2.10 | 3.2.10 |
pip/Plone | <5.2.3 | 5.2.3 |
Plone Plone | <5.2.3 | |
<5.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-28736 is high with a CVSS score of 8.8.
CVE-2020-28736 allows XXE attacks by utilizing a feature that is protected by an unapplied permission.
Only users with the Manager role have access to the feature protected by the unapplied permission in CVE-2020-28736.
Plone versions up to 5.2.3 are affected by CVE-2020-28736.
To fix CVE-2020-28736, update to Plone version 5.2.3 or higher.