Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| Plone(PyPI) | 0 | 5.2.3 | N/A |
| plone.app.event(PyPI) | 0 | 3.2.10 | N/A |
| plone.app.theming(PyPI) | 0 | 4.1.6 | N/A |
| plone.app.dexterity(PyPI) | 0 | 2.6.8 | N/A |
| plone.supermodel(PyPI) | 0 | 1.6.3 | N/A |
CVSS Metrics