Executive brief
Plone is a web content management system. A flaw in the schema editor allows authenticated managers to upload malicious XML files that could read sensitive files from the server or perform other XML-based attacks. The vulnerability requires Manager-level privileges, limiting exposure but potentially allowing internal attackers to access confidential data.
Technical details
This is an XML External Entity (XXE) injection vulnerability in Plone's schema editor feature. The vulnerable component fails to properly restrict or disable XML external entity processing when parsing schema definition files. An authenticated user with Manager role can exploit this by submitting specially crafted XML that references external entities to read arbitrary files (information disclosure), perform SSRF attacks, or cause denial of service through billion laughs attacks. The vulnerability affects Plone versions before 5.2.3 and several related packages (plone-app-event before 3.2.10, plone-app-theming before 4.1.6, plone-app-dexterity before 2.6.8, and others). Patches are available in the fixed versions listed.
Affected products
- Plone Plone before 5.2.3
- Plone plone-app-event before 3.2.10
- Plone plone-app-theming before 4.1.6
- Plone plone-app-dexterity before 2.6.8
- Plone plone-supermodel unknown
Timeline
- 2020-12-30: disclosed: Vulnerability reported to NVD
- 2021-04-07: advisory: GitHub Security Advisory GHSA-2c8c-84w2-j38j published
- 2020-12: patched: Fixes available in Plone 5.2.3 and corresponding versions of affected packages