Description
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
Remediation
References
Related Vulnerabilities
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.30)
WordPress Plugin Subscribe2 Unspecified Vulnerability (10.20.5)
WordPress Plugin Mitsol Social Post Feed Cross-Site Scripting (1.10)
Magento CVE-2020-9579 Vulnerability (CVE-2020-9579)
WordPress Plugin Duplicator-WordPress Migration Remote Code Execution (1.2.40)