VYPR
Unrated severityNVD Advisory· Published Apr 23, 2021· Updated Aug 4, 2024

CVE-2020-17542

CVE-2020-17542

Description

Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component.

Affected products

2
  • dotCMS/dotCMSdescription
  • Dotcms/Dotcmsllm-fuzzy
    Range: = 5.1.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.