Vulnerabilities
Vulnerable Software
Dotcms:  >> Dotcms  >> 4.0.0  Security Vulnerabilities
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-11-26
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
CVSS Score
7.2
EPSS Score
0.005
Published
2018-02-19
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
CVSS Score
7.2
EPSS Score
0.005
Published
2018-02-19


Contact Us

Shodan ® - All rights reserved