Apache Cocoon 2.1.12 is susceptible to XML injection. When using the StreamGenerator, the code parses a user-provided XML. A specially crafted XML, including external system entities, can be used to access any file on the server system.
View the template here CVE-2020-11991.yaml
References:
https://github.com/ARPSyndicate/cvemon