VYPR
Medium severity5.4NVD Advisory· Published Apr 23, 2021· Updated Jun 17, 2026

CVE-2020-17542

CVE-2020-17542

Description

Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component.

Affected products

3
  • Dotcms/Dotcms2 versions
    cpe:2.3:a:dotcms:dotcms:5.1.5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:dotcms:dotcms:5.1.5:*:*:*:*:*:*:*
    • (no CPE)range: =5.1.5
  • dotCMS/dotCMSdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.