Description Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. Remediation References CVE-2020-28734 Related Vulnerabilities Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4297) ATutor Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-12169) Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-42128) Dolibarr Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-17899) LiteSpeed Web Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-4871) Severity High Classification CVE-2020-28734 CWE-611 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities