Show filters
57 Total Results
Displaying 11-20 of 57
Sort by:
Attacker Value
Unknown
CVE-2022-35740
Disclosure Date: November 10, 2022 (last updated December 22, 2024)
dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using a semicolon in a URL to introduce a matrix parameter. (This is also fixed in 5.3.8.12, 21.06.9, and 22.03.2 for LTS users.) Some Java application frameworks, including those used by Spring or Tomcat, allow the use of matrix parameters: these are URI parameters separated by semicolons. Through precise semicolon placement in a URI, it is possible to exploit this feature to avoid dotCMS's path-based XSS prevention (such as "require login" filters), and consequently access restricted resources. For example, an attacker could place a semicolon immediately before a / character that separates elements of a filesystem path. This could reveal file content that is ordinarily only visible to signed-in users. This issue can be chained with other exploit code to achieve XSS attacks against dotCMS.
0
Attacker Value
Unknown
CVE-2022-37431
Disclosure Date: August 05, 2022 (last updated November 08, 2023)
A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has XSS_PROTECTION_ENABLED=false. NOTE: the vendor disputes this because the current product behavior, in effect, has XSS_PROTECTION_ENABLED=true in all configurations
0
Attacker Value
Unknown
CVE-2020-19138
Disclosure Date: September 08, 2021 (last updated November 29, 2024)
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src/main/java/com/dotmarketing/filters/CMSFilter.java".
0
Attacker Value
Unknown
CVE-2020-18875
Disclosure Date: August 18, 2021 (last updated November 29, 2024)
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
0
Attacker Value
Unknown
CVE-2021-35361
Disclosure Date: July 09, 2021 (last updated November 28, 2024)
A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/links of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2021-35360
Disclosure Date: July 09, 2021 (last updated November 28, 2024)
A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/containers of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2021-35358
Disclosure Date: July 09, 2021 (last updated November 28, 2024)
A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters.
0
Attacker Value
Unknown
CVE-2020-17542
Disclosure Date: April 23, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component.
0
Attacker Value
Unknown
CVE-2020-27848
Disclosure Date: December 30, 2020 (last updated November 28, 2024)
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2020-35274
Disclosure Date: December 21, 2020 (last updated November 28, 2024)
DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.
0