Sensitive Information Exposure in Plone CMS
CVE-2021-33926
8.8HIGH
What is CVE-2021-33926?
In Plone CMS, versions 5.2.4 through 4.3.20 are vulnerable to a flaw allowing attackers to exploit its RSS feed functionality. This weakness enables unauthorized access to sensitive information by leveraging a blind Server-Side Request Forgery (SSRF) attack, which can potentially expose internal resources and data. Implementing the latest patches and following security best practices is essential to mitigate these risks.
