XML External Entity Vulnerability in Plone by Plone Foundation
CVE-2020-28734
8.8HIGH
What is CVE-2020-28734?
An XML External Entity (XXE) vulnerability exists in Plone versions before 5.2.3, permitting attackers to exploit features intended only for users with Manager role access. This flaw can lead to unauthorized exposure of sensitive files or enable other attacks, emphasizing the need for timely updates and security considerations.
