Apache Cocoon 2.1.12 is susceptible to XML injection. When using the StreamGenerator, the code parses a user-provided XML. A specially crafted XML, including external system entities, can be used to access any file on the server system.
id: CVE-2020-11991
info:
name: Apache Cocoon 2.1.12 - XML Injection
author: pikpikcu
severity
...