Server-side Request Forgery in Plone Affects Multiple Themes and Frameworks
CVE-2021-33511
7.5HIGH
What is CVE-2021-33511?
A vulnerability in Plone versions up to 5.2.4 allows for Server-side Request Forgery (SSRF) through the lxml parser. This issue can impact Diazo themes, Dexterity TTW schemas, and modeleditors found within various Plone applications. Attackers can exploit this vulnerability to make unauthorized requests from the perspective of the server, potentially leading to data exposure and increased risks within the web application's environment.
