Description
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
Remediation
References
Related Vulnerabilities
Jenkins CVE-2018-1000408 Vulnerability (CVE-2018-1000408)
WordPress Plugin Live Chat-Live support Cross-Site Request Forgery (3.1.0)
WordPress Plugin Auto Featured Image Arbitrary File Upload (1.2)
MySQL CVE-2020-14619 Vulnerability (CVE-2020-14619)
WordPress Plugin Job Board by BestWebSoft Cross-Site Scripting (1.1.3)