HIGH 8.8 PyPI
Improper Restriction of XML External Entity Reference in Plone
GHSA-wq6x-g685-w5f2 · CVE-2020-28734 · PYSEC-2020-246 · PYSEC-2026-2880 · PYSEC-2026-2883 · PYSEC-2026-2886 · PYSEC-2026-736
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-28734
- WEB https://github.com/plone/Products.CMFPlone/issues/3209
- WEB https://dist.plone.org/release/5.2.3/RELEASE-NOTES.txt
- ADVISORY https://github.com/advisories/GHSA-wq6x-g685-w5f2
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2020-246.yaml
- WEB https://www.misakikata.com/codes/plone/python-en.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes