Adobe Experience Manager 6.5, 6.4, 6.3 and 6.2 are susceptible to XML external entity injection. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
View the template here CVE-2019-8086.yaml
References:
https://helpx.adobe.com/security/products/experience-manager/apsb19-48.html