PYSEC-2026-2879
Dashboard / Vulnerabilities / PYSEC-2026-2879
PYSEC-2026-2879
Summary: Improper Restriction of XML External Entity Reference in Plone
Details: Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
References: https://nvd.nist.gov/vuln/detail/CVE-2020-28736, https://github.com/plone/Products.CMFPlone/issues/3209, https://dist.plone.org/release/5.2.3/RELEASE-NOTES.txt, https://github.com/advisories/GHSA-2c8c-84w2-j38j, https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2020-248.yaml, https://www.misakikata.com/codes/plone/python-en.html, https://pypi.org/project/plone-app-dexterity
Affected packages
Package
Name: plone-app-dexterity
Purl: pkg:pypi/plone-app-dexterity
Affected ranges
Type: ECOSYSTEM
Events:
