Description
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
Remediation
References
Related Vulnerabilities
PHP Out-of-bounds Write Vulnerability (CVE-2017-9226)
MySQL CVE-2021-2481 Vulnerability (CVE-2021-2481)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-2922)
IBMHttpServer Other Vulnerability (CVE-2006-3918)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1488)