Plone · Plone · CVE-2021-33511
**Name of the Vulnerable Software and Affected Versions**
Plone versions prior to 5.2.5
**Description**
The issue allows for Server-Side Request Forgery (SSRF) via the lxml parser. This affects various components including Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.
**Recommendations**
For Plone versions prior to 5.2.5, update to version 5.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the lxml parser until a patch is available.