PyPI package
plone.app.event
pkg:pypi/plone.app.event
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-28736 | — | < 3.2.10 | 3.2.10 | Dec 30, 2020 | Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role). | ||
| CVE-2020-28735 | — | < 3.2.10 | 3.2.10 | Dec 30, 2020 | Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role). | ||
| CVE-2020-28734 | — | < 3.2.10 | 3.2.10 | Dec 30, 2020 | Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. |
- CVE-2020-28736Dec 30, 2020affected < 3.2.10fixed 3.2.10
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
- CVE-2020-28735Dec 30, 2020affected < 3.2.10fixed 3.2.10
Plone before 5.2.3 allows SSRF attacks via the tracebacks feature (only available to the Manager role).
- CVE-2020-28734Dec 30, 2020affected < 3.2.10fixed 3.2.10
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.