
Cloud Vulnerability DB
A community-led vulnerabilities database
Plone before version 5.2.3 contains a vulnerability that allows XXE (XML External Entity) attacks through a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata. This permission is only available to users with the Manager role (MITRE CVE, Plone Release Notes).
The vulnerability is related to XML handling in Plone's schema editor functionality. The issue specifically affects features protected by the plone.schemaeditor.ManageSchemata permission, which is restricted to users with Manager role access (MITRE CVE).
Since this vulnerability requires an attacker to already have Manager or Site Administrator rights, the impact is considered limited. The vulnerability could potentially lead to information disclosure through XXE attacks when exploited by users with elevated privileges (Plone Release Notes).
The exploitability of this vulnerability is limited due to the requirement of having Manager role privileges to access the affected functionality. An attacker would need to already have high-level administrative access to the Plone installation to attempt exploitation (MITRE CVE).
The vulnerability has been fixed in Plone version 5.2.3. Users should upgrade to this version or later to address the security issue. The Plone Security Team determined that a hotfix was not necessary due to the elevated privileges required for exploitation (Plone Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."