Critical severity9.8NVD Advisory· Published Dec 19, 2016· Updated May 6, 2026
CVE-2016-2355
CVE-2016-2355
Description
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- dotcms.com/security/SI-35nvdPatchVendor Advisory
- github.com/dotCMS/core/issues/8848nvdIssue TrackingPatch
- www.securityfocus.com/bid/94992nvd
News mentions
0No linked articles in our index yet.