CVE-2020-28736
30.12.2020, 19:15
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).Enginsight
Vendor | Product | Version |
---|---|---|
plone | plone | 𝑥 < 5.2.3 |
𝑥
= Vulnerable software versions
References