CVE-2020-28736: XEE
Published Dec 30, 2020
·Updated
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
Affected Software
6 affected componentsFixes available
pip/plone.supermodel<1.6.3
1.6.3
pip/plone.app.dexterity<2.6.8
2.6.8
pip/plone.app.theming<4.1.6
4.1.6
pip/plone.app.event<3.2.10
3.2.10
pip/Plone<5.2.3
5.2.3
Plone plone<5.2.3
Remediation
Patch Available
Event History
Dec 30, 2020
CVE Published
via MITRE·06:40 PM
Data Sourced
via MITRE·06:40 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 7, 2021
Advisory Published
09:14 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-28736?
The severity of CVE-2020-28736 is high with a CVSS score of 8.8.
2
How does CVE-2020-28736 allow XXE attacks?
CVE-2020-28736 allows XXE attacks by utilizing a feature that is protected by an unapplied permission.
3
What roles have access to the feature protected by the unapplied permission in CVE-2020-28736?
Only users with the Manager role have access to the feature protected by the unapplied permission in CVE-2020-28736.
4
Which versions of Plone are affected by CVE-2020-28736?
Plone versions up to 5.2.3 are affected by CVE-2020-28736.
5
How can I fix CVE-2020-28736?
To fix CVE-2020-28736, update to Plone version 5.2.3 or higher.